CyberMax
Home › Exploited CVEs

GitLab known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 5 GitLab CVEs as exploited in the wild. 3 were added in the last 12 months (latest 2026-09-11), and 1 are known to be used in ransomware campaigns.

GitLab CVEs added to CISA KEV per year
2021: 1202112024: 1202412026: 320263

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected GitLab products

Community and Enterprise Editions (2), Community Edition and Enterprise Edition (1), GitLab (1), GitLab CE/EE (1).

All GitLab CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-85706Community Edition and Enterprise EditionCommunity Edition and Enterprise Edition Path Traversal2026-09-112026-09-1491.4%–
CVE-2021-22175GitLabServer-Side Request Forgery (SSRF)2026-02-182026-03-1153.4%–
CVE-2021-39935Community and Enterprise EditionsCommunity and Enterprise Editions Server-Side Request Forgery (SSRF)2026-02-032026-02-2435.6%–
CVE-2023-7028GitLab CE/EECommunity and Enterprise Editions Improper Access Control2024-05-012024-05-2294.6%–
CVE-2021-22205Community and Enterprise EditionsCommunity and Enterprise Editions Remote Code Execution2021-11-032021-11-1799.7%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors