vulnerability
Critical GitLab Flaw Exploited Shortly After Disclosure
Critical
Summary
A critical vulnerability in GitLab (CVE-2026-19478) was quickly exploited by threat actors shortly after its disclosure. The code injection flaw allowed unauthenticated users to delete public projects and modify user data via GraphQL, and WatchTower detected in-the-wild exploitation attempts within days. This highlights a concerning trend of rapid exploitation following vulnerability announcements, particularly with the potential for AI-powered attackers to quickly replicate and deploy exploits.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data