SevenTnewSAI & tech news, explained

Cybersecurity · CISA KEV Catalog

CISA's new patch rulebook turns one GitLab flaw into a forensic problem

CVE-2026-85706 is a path traversal bug in GitLab CE and EE, and it is being exploited. The KEV listing also puts it at the front of a federal queue reshaped by BOD 26-04, which now asks agencies to prove they were not breached before patching.

Emmanuel Fabrice Omgbwa Yasse AI-assisted

2026-09-26 · 4 min read

CISA's new patch rulebook turns one GitLab flaw into a forensic problem

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog: CVE-2026-85706, a path traversal flaw in GitLab Community Edition and Enterprise Edition. The listing rests on evidence of active exploitation, the same bar that put a Progress LoadMaster command injection flaw on the must-patch list, according to the LoadMaster KEV entry.

A flaw earns a place in the KEV Catalog on evidence that it is already being used. CISA holds outside nominations to the same bar: a CVE ID, proof of exploitation, and clear mitigation guidance. That last requirement is what makes the catalog a work queue instead of a warning list. Every listed CVE arrives with a documented way to close it.

The GitLab flaw behind the listing

Path traversal is a familiar class of bug, and CISA treats it that way. The agency describes the technique as a frequent attack vector for malicious actors and a significant risk to the federal enterprise.

The mechanics explain why. A traversal flaw lets an attacker reach files outside the directory an application means to serve from, so the damage scales with whatever sits behind that boundary. The same bug on two installs can mean two very different outcomes.

CISA's notice names the affected editions and the vulnerability class. It stops short of naming affected version ranges or a fixed release.

BOD 26-04 turns the catalog into a ranking system

The directive attached to this addition is Binding Operational Directive 26-04, Prioritizing Security Updates Based on Risk. It sets vulnerability management requirements for Federal Civilian Executive Branch agencies and directs them to remediate high-risk flaws quickly, where high-risk means a KEV-listed CVE sitting on a publicly exposed asset that grants total control of that asset after exploitation. Lower-risk vulnerabilities get deferred.

That definition is the operative part. It gives an agency a way to rank a queue it cannot empty all at once, and it ties the ranking to two variables: whether the asset is reachable from the internet, and how much of the system a successful exploit hands over. CISA encourages organizations outside government to adopt the same risk-based approach and to prioritize KEV-listed CVEs.

The look-back clause: proving you were not already breached

BOD 26-04 adds a second expectation that is easy to skim past: agencies must check whether threat actors compromised a system before the patch went on. The same duty now sits on other listings under the directive, including the Cisco firewall flaw added to KEV.

That splits the work into two jobs. Closing a path traversal restores the boundary the application was supposed to have, and nothing more. It cannot tell an agency whether data left the system while the flaw was open. The directive sets out when the check happens. It does not prescribe how to run it or what has to be documented afterward. Patching, on its own, no longer counts as finished work under BOD 26-04.

A federal mandate that reads as a global signal

The directive binds FCEB agencies only. The reach of the catalog is wider by design. CISA encourages all organizations to adopt risk-based vulnerability management and to prioritize remediation of KEV entries, and it says it will keep adding vulnerabilities that meet its criteria.

Nominations stay open through CISA's KEV Nomination Form, and the criteria do not move: evidence of exploitation first, mitigation guidance alongside it. Because the standard is evidence rather than severity, the catalog records what attackers are already using instead of predicting what they might. For a security team holding more findings than working hours, that is a usable filter.

What the directive leaves unresolved for GitLab operators

A federal agency now has a defined queue position and a detection obligation attached to this CVE. Everyone else running Community Edition or Enterprise Edition has a judgment call.

Non-federal operators get no mandated remediation window and no required compromise check. They get CISA's encouragement, which carries no deadline and no reporting obligation with it. How much that matters depends on exposure: a GitLab instance reachable from the internet is a different problem from one sitting behind a VPN and an allowlist.

The catalog entry tells an operator that a GitLab traversal is being exploited somewhere. BOD 26-04 tells a federal agency what to do about that within a fixed set of rules. For the rest of the install base, the guidance stays the same: treat the listing as urgent, patch, and then work out whether the compromise already happened.

Get the tech essentials in 3 minutes every morning

One email, every weekday, with what actually matters in AI and tech.