GitLab CVE-2026-85706: Patch the File Read, Then Rotate What It Exposed
CISA lists GitLab CVE-2026-85706 as exploited. Self-managed administrators must upgrade to 19.3.2, 19.2.6, or 19.1.8 or later, hunt the repository commits API, and treat readable secrets as potentially compromised.