#3
The Hacker News
general
August 21, 2026 at 07:04 UTC
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
By [email protected] (The Hacker News)
AI Summary
CVE-2026-19478, a CVSS 9.4 unauthenticated code injection vulnerability in GitLab, was exploited in the wild within days of public disclosure, according to watchTowr. The flaw allows attackers to modify or delete publicly accessible GitLab projects and rewrite their data without authentication, posing an immediate risk to organizations running self-hosted GitLab instances.
Relevance score: 89.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →