GitLab known exploited vulnerabilities
CISA lists 5 GitLab CVEs as exploited in the wild. 3 were added in the last 12 months (latest 2026-09-11), and 1 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2021-22205 (Community and Enterprise Editions): EPSS 99.7%, added 2021-11-03
- CVE-2023-7028 (GitLab CE/EE): EPSS 94.6%, added 2024-05-01
- CVE-2026-85706 (Community Edition and Enterprise Edition): EPSS 91.4%, added 2026-09-11
- CVE-2021-22175 (GitLab): EPSS 53.4%, added 2026-02-18
- CVE-2021-39935 (Community and Enterprise Editions): EPSS 35.6%, added 2026-02-03
Most affected GitLab products
Community and Enterprise Editions (2), Community Edition and Enterprise Edition (1), GitLab (1), GitLab CE/EE (1).
All GitLab CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-85706 | Community Edition and Enterprise Edition | Community Edition and Enterprise Edition Path Traversal | 2026-09-11 | 2026-09-14 | 91.4% | – |
| CVE-2021-22175 | GitLab | Server-Side Request Forgery (SSRF) | 2026-02-18 | 2026-03-11 | 53.4% | – |
| CVE-2021-39935 | Community and Enterprise Editions | Community and Enterprise Editions Server-Side Request Forgery (SSRF) | 2026-02-03 | 2026-02-24 | 35.6% | – |
| CVE-2023-7028 | GitLab CE/EE | Community and Enterprise Editions Improper Access Control | 2024-05-01 | 2024-05-22 | 94.6% | – |
| CVE-2021-22205 | Community and Enterprise Editions | Community and Enterprise Editions Remote Code Execution | 2021-11-03 | 2021-11-17 | 99.7% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors