Home / Aug 22, 2026 / Story
0
#3 The Hacker News general August 21, 2026 at 07:04 UTC

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

By [email protected] (The Hacker News)

AI Summary

CVE-2026-19478, a CVSS 9.4 unauthenticated code injection vulnerability in GitLab, was exploited in the wild within days of public disclosure, according to watchTowr. The flaw allows attackers to modify or delete publicly accessible GitLab projects and rewrite their data without authentication, posing an immediate risk to organizations running self-hosted GitLab instances.

Relevance score: 89.0/100

# More from August 22