Exploited CVEs / By vendor / GitLab

GitLab vulnerabilities actively exploited

5 GitLab CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2026-85706 (Community Edition and Enterprise Edition, added 2026-09-11). 1 of the 5 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

5 exploited CVEs1 ransomware-linked
Senserva AI Opinion and rich prompt for GitLab exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

All GitLab entries

CVEProductAdded to KEVSignals
CVE-2026-85706Community Edition and Enterprise Edition2026-09-11CVSS 10.0, EPSS 1%
CVE-2021-22175GitLab2026-02-18CVSS 9.8, EPSS 53%
CVE-2021-39935Community and Enterprise Editions2026-02-03CVSS 7.5, EPSS 36%
CVE-2023-7028GitLab CE/EE2024-05-01CVSS 9.8, EPSS 95%
CVE-2021-22205Community and Enterprise Editions2021-11-03ransomware, CVSS 10.0, EPSS 100%

Common questions about exploited GitLab CVEs

Which GitLab vulnerabilities are actively exploited?

As of September 2026, 5 GitLab CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. 1 are linked to ransomware campaigns.

What is the newest exploited GitLab CVE?

CVE-2026-85706, affecting Community Edition and Enterprise Edition, added to the CISA KEV catalog on 2026-09-11. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these GitLab CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited GitLab CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest GitLab KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed once a day (early morning US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.