Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Women’s football shouldn’t have to copy a men’s game that isn’t working – just look at Ted Lasso | Karen Dobres

    August 21, 2026

    US debt has hit $40tn – Will that be a wake-up call?

    August 21, 2026

    The drone war is coming for global shipping – POLITICO

    August 21, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Women’s football shouldn’t have to copy a men’s game that isn’t working – just look at Ted Lasso | Karen Dobres
    • US debt has hit $40tn – Will that be a wake-up call?
    • The drone war is coming for global shipping – POLITICO
    • Burnham to chair growth meeting call at No 10 North – UK politics live | Politics
    • Starmer donates biography of himself to Downing Street library
    • Ukraine seeks Musk’s help to hit Russian missile launchers
    • The Single English County Saying No to Palantir
    • How AI coding tools are contributing to the popularity of JavaScript
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 21
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 21, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 21, 2026Vulnerability / Enterprise Security

    A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.

    The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring credentials, user interaction, or obscure configuration.

    The following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) are affected by the flaw –

    • 18.2 before 18.11.11
    • 19.0 before 19.0.8
    • 19.1 before 19.1.6
    • 19.2 before 19.2.4

    In an alert released earlier this week, GitLab said the issue could be exploited via a GraphQL directive. Fixes for the flaw were rolled out in GitLab CE and EE versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11.

    Preemptive exposure management firm watchTowr told The Hacker News that it was able to reproduce the vulnerability within minutes of its disclosure, adding that it observed in-the-wild exploitation against its honeypot network.

    Cybersecurity

    “This is the new reality of vulnerability reproduction and exploitation, where AI [artificial intelligence]-enabled attackers are able to compress the time from disclosure to exploitation and ‘waiting until the next patch cycle’ is often too late,” Jake Knott, principal security researcher at watchTowr, said.

    “Organizations that haven’t patched yet should hunt through web logs for requests containing ‘@gl_introduced,’ and look for signs of probes or attempted exploitation.”

    watchTowr also noted that the vulnerability’s impact goes beyond the ability to modify or delete public projects, adding “an attacker can delete entire repositories, forge merge records to make it appear as if a fix landed when it didn’t, and ban project maintainers.”

    The development once again highlights how AI is rapidly changing the speed and the scale of the attacks, making it crucial that users apply the updates in a timely fashion.

    Organizations running internet-facing self-hosted GitLab instances should prioritize upgrading to a patched release. If immediate patching is not possible, it’s advised to restrict unauthenticated access to “/api/graphql”, or remove public repository access entirely as a mitigation.

    active CVE202619478 days Disclosure exploitation GitLab
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft Rolls Out 22 Fresh Security Patches

    New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

    AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

    ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

    Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

    Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Women’s football shouldn’t have to copy a men’s game that isn’t working – just look at Ted Lasso | Karen Dobres

    August 21, 2026

    US debt has hit $40tn – Will that be a wake-up call?

    August 21, 2026

    The drone war is coming for global shipping – POLITICO

    August 21, 2026

    Burnham to chair growth meeting call at No 10 North – UK politics live | Politics

    August 21, 2026
    Latest Posts

    New Dysphoria DDoS botnet spreads to 200k devices worldwide

    July 28, 2026

    OpenAI’s biggest threat may just be open AI

    July 28, 2026

    6 Takeaways From Michigan’s Senate Debate Between Abdul El-Sayed and Haley Stevens

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Women’s football shouldn’t have to copy a men’s game that isn’t working – just look at Ted Lasso | Karen Dobres

    August 21, 2026

    US debt has hit $40tn – Will that be a wake-up call?

    August 21, 2026

    The drone war is coming for global shipping – POLITICO

    August 21, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.