<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/marques/gitlab.xml</id>
  <title>Exploit Radar: exploited GitLab vulnerabilities</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities for GitLab products.</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/marques/gitlab.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/marques/gitlab/"/>
  <updated>2026-09-11T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-85706/</id>
    <title>CVE-2026-85706 — GitLab Community / Enterprise Edition (CE/EE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-85706/"/>
    <updated>2026-09-11T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from GitLab; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 11, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-22175/</id>
    <title>CVE-2021-22175 — GitLab Community / Enterprise Edition (CE/EE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-22175/"/>
    <updated>2026-02-18T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from GitLab; if none are available, stop using the product. For cloud services, follow the guidance from GitLab. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on February 18, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-39935/</id>
    <title>CVE-2021-39935 — GitLab Community / Enterprise Edition (CE/EE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-39935/"/>
    <updated>2026-02-03T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from GitLab; if none are available, stop using the product. For cloud services, follow the guidance from GitLab. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on February 3, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-7028/</id>
    <title>CVE-2023-7028 — GitLab Community / Enterprise Edition (CE/EE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-7028/"/>
    <updated>2024-05-01T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from GitLab; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on May 1, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-22205/</id>
    <title>CVE-2021-22205 — GitLab Community / Enterprise Edition (CE/EE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-22205/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from GitLab. CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
</feed>
