Vulnerabilities & Patching
GitLab CVE-2026-19478 Exploited Days After Disclosure; Unauthenticated Flaw Hits Public Repos
Threat actors began exploiting GitLab CVE-2026-19478 roughly two to three days after disclosure, according to watchTowr. The critical, unauthenticated GraphQL flaw lets attackers modify or delete public projects and user data on unpatched self-managed instances. Fixed builds shipped August 17.