Skip to content

Enterprise software, read for what it costs and who signs for it.

Security

GitLab patched a perfect-10 flaw Thursday. Attackers were exploiting it Friday.

CVE-2026-85706 in GitLab carries a CVSS score of 10 and was being exploited one day after the patches were announced, SecurityWeek reported.

ERP LEADERS news desk · · First reported by SecurityWeek · Edition no. 6

SecurityWeek describes it as a path traversal issue that lets unauthenticated users read arbitrary files from the GitLab server.

Attack surface firm watchTowr observed the first in-the-wild exploitation attempts. Jake Knott, its head of threat intelligence, said: "This is the second instance of a critical-severity GitLab vulnerability in recent weeks, following the previous GraphQL code injection that was almost immediately actively exploited."

SecurityWeek reported that all Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6 and 19.3 before 19.3.2 are affected, and that the same release closed 17 other flaws.

A file-read bug on a build server is a credentials problem before it is a code problem.

After you patch, which pipeline tokens that can reach your ERP get rotated, and who checks what they did last week?

Sources

Spotted an error? Tell us. Every correction is logged on Standards.

Your reading room

Companies in this story
GitLab

For your next steering committee

Questions for your own programme. They are not findings about any company in this story.

  1. 1Ask when systems of this kind in your landscape were last patched, and who confirms it.
  2. 2Ask which finance and ERP accounts can be reached from outside, and how each sign-in is protected.
  3. 3Ask how long a restore took the last time it was tested.

Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01

Founding reader view is on in this browser. It is a reading view, not secure access. Print the working sheet

Founding reader

Welcome back. · Issue 01

1 comment under this story on LinkedIn. Read the discussion

Keep reading

The ERP LEADERS brief Get issue 01