Severity Daily

IT and AI security incidents, checked against the primary source

GitLab’s 10.0 went on KEV Thursday with a Monday deadline, and NVD’s record still doesn’t carry it

PATCH NOW — GitLab's 10.0 went on KEV Thursday with a Monday deadline, and NVD's record still doesn't carry it

Written by

in

CISA added the GitLab path traversal to its Known Exploited Vulnerabilities catalog on Thursday with a remediation deadline of Monday, September 14, 2026 — a date this site declined to report twelve hours ago, because the source that carries it was misread as stale.

What happened

CVE-2026-85706 is in the Known Exploited Vulnerabilities catalog. Its entry carries a dateAdded of 2026-09-11 and a dueDate of 2026-09-14. Federal civilian agencies have until Monday.

The catalog file that carries it is version 2026.09.11, with a dateReleased of 2026-09-11T19:32:16.8993Z — 7:32 p.m. UTC on Thursday, September 11. It holds 1,709 entries. Four of them were added that day: the two JFrog Artifactory flaws this site covered on September 11, a ConnectWise ScreenConnect flaw covered separately today, and GitLab.

The GitLab entry is titled “GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability.” Its short description reads: “GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.” It is filed under CWE-35. Its knownRansomwareCampaignUse value is Unknown, and its forensicTriage value is Yes — the BOD 26-04 obligation that requires an agency to remediate inside the window and also determine whether the asset was already compromised.

The flaw itself is unchanged from what this site reported on the evening of September 11. GitLab’s own record self-assigns CVSS 10.0 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. The description names the affected range as “all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2,” which is the same boundary that produced this site’s earlier finding: there is no fixed 18.x build. An operator on 18.7 through 19.1.7 has one remedy, and it is 19.1.8.

The record NVD still has not updated

NVD republishes CISA’s catalog fields verbatim into CVE records — cisaExploitAdd, cisaActionDue, cisaVulnerabilityName, and cisaRequiredAction. As of 3:55 p.m. UTC on Saturday, September 12, the NVD record for CVE-2026-85706 carries none of them. Its lastModified value is 2026-09-12T04:16:44.907 and its vulnStatus is Received. That is more than twenty-five hours after the catalog was released, and the record still does not say the flaw is on KEV.

The gap is not a general lag. CVE-2026-84869, the ConnectWise ScreenConnect flaw added to the catalog in the same release on the same day, was updated in NVD at 2026-09-11T19:57:11.373 — twenty-five minutes after the catalog went out — and it carries cisaExploitAdd of 2026-09-11 and cisaActionDue of 2026-09-14 in full. The two JFrog records from the same release picked up their CISA fields at 2026-09-12T04:16:32.483 and 2026-09-12T04:16:33.587. GitLab’s record was written twelve seconds after those two, in the same batch, and came away with nothing.

Three of the four September 11 additions synchronized. One did not, and it is the one carrying a 10.0 and the shortest clock.

The correction

This site published a story at 6:47 a.m. UTC today reporting that CISA’s coordinator had flagged the flaw as actively exploited in an SSVC block, and stating that we could not confirm the KEV listing or the September 14 deadline that other outlets were reporting. That story said the cisagov/kev-data GitHub mirror was “stale at catalog version 2026.08.27.”

It was not. The mirror serves catalog version 2026.09.11, released the previous evening, and it contains the GitLab entry. The file is about 1.7 MB, and it is retrievable in full over plain HTTP. The earlier read of it was wrong, and the conclusion drawn from that read — that no federal deadline could be confirmed — was wrong with it. A dated note now sits at the point of the error in that story, and the Corrections page carries the entry.

What the earlier story got right is the part that still stands: NVD’s record does not carry the deadline, and the reasoning about the synchronization batch was correct as far as it went. The error was treating one unreadable source as an absent fact.

Because that read is now load-bearing, it was checked against everything this site has already published from NVD. Twelve KEV dates reported here since September 8 — the two JFrog entries due September 25, both MikroTik RouterOS entries due September 13, Chrome due September 23, Fortinet, Citrix NetScaler, and Cisco FMC all due September 12, Adobe Commerce and N-able N-central due September 11, and both Windows entries due September 22 — match the mirror exactly, in every dateAdded and every dueDate. So does an absence: CVE-2026-67276, the third MikroTik flaw this site reported as unlisted, is still not in the catalog.

Why it matters

A federal remediation clock exists in exactly one authoritative place, and every other representation of it is a copy. When the copies disagree, the question of which one an organization is looking at stops being a curiosity and becomes the difference between acting on Saturday and acting on Tuesday.

Most vulnerability management tooling does not read CISA’s catalog file. It reads NVD, or a vendor feed that reads NVD, because NVD is the one interface that carries scores, affected ranges, weaknesses, and KEV status in a single record. For twenty-five hours and counting, that interface has been telling every downstream consumer that CVE-2026-85706 has no federal deadline. An agency whose scanner enriches from NVD has a 10.0 sitting in its queue with no clock attached to it, and Monday is two days away.

The second-order problem is that the failure is silent in both directions. Nothing in the NVD record announces that its CISA fields are pending. A missing cisaActionDue looks identical whether the flaw was never listed, was listed and has not synchronized, or was listed and later removed. This site made exactly that mistake this morning, with the primary source in reach and a method already written down for reaching it — which is a reasonable illustration of how the failure behaves for anyone else relying on the same field.

There is also the matter of what the catalog now says that it did not used to. Every one of the 1,709 entries carries a forensicTriage value, and 51 of them read Yes. That is the BOD 26-04 obligation rendered as a machine-readable field, per entry, which is a meaningful improvement over the situation this publication has repeatedly flagged: the directive’s own deadline schedule is published as PNG images in an appendix, with no alt text, and public transcriptions of it disagree. The forensicTriage flag does not resolve that — it still does not tell anyone which variable combination earns which band — but it does mean an agency reading the catalog directly can see that this entry carries the triage obligation without having to derive it from a picture. None of that reaches a defender who is reading the NVD record for this CVE, because the NVD record for this CVE has no CISA fields in it at all.

What to do

Upgrade self-managed GitLab to 19.3.2, 19.2.6, or 19.1.8. There is no fixed 18.x build; installations on 18.7 through 19.1.7 must move to 19.1.8 or later. GitLab.com and Dedicated are on the patched version already.

Federal civilian agencies: the deadline is Monday, September 14, 2026, and the entry carries the forensic-triage obligation, which means remediation alone does not close it. Assess whether the asset was compromised before the patch landed.

If your vulnerability management platform sources KEV status from NVD, do not rely on it for this CVE this weekend. Check the catalog file directly. Anyone maintaining internal KEV automation should treat a missing cisaActionDue as unknown rather than as absent, and reconcile against the catalog rather than against the CVE record.

Sourcing note

The KEV entry, its dateAdded, dueDate, forensicTriage, requiredAction, short description, and CWE were read from the full catalog JSON published at the cisagov/kev-data mirror on GitHub, retrieved in full on September 12, 2026. cisa.gov returns 403 to automated fetching, so the mirror is the route used; the file carries CISA’s own catalogVersion and dateReleased metadata, and its contents were cross-checked against twelve KEV dates independently confirmed from NVD records over the past five days, all of which matched. CVE details, timestamps, and the absence of CISA fields were read from the NVD API records for CVE-2026-85706 and CVE-2026-84869 on September 12, 2026 at approximately 3:55 p.m. UTC.

Unresolved: why the GitLab record did not receive its CISA fields when three other entries from the same catalog release did. NVD publishes no status for pending KEV synchronization, and there is no way from here to distinguish a queue failure from a deliberate hold. We also cannot establish from here whether the mirror was briefly serving an older catalog version at the time of this morning’s read or was simply misread; the file it serves now was released before that read took place, which points to the latter.

Previous coverage: GitLab patches a 10.0 unauthenticated file read, and no 18.x build in the release carries the fix (September 11) and CISA’s coordinator marks the GitLab 10.0 as actively exploited, and GitLab’s own advisory still says nothing (September 12, corrected).