Cyber Resilience
← All news
Confirmed

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

Our takewatchTowr reports CVE-2026-19478 (CVSS 9.4) in GitLab under active exploitation within hours of disclosure: unauthenticated code injection letting attackers modify or delete public projects. Patch immediately if you self-host; hosted users are unaffected.
Sources (2)
What this means for you — Security leader:Apply the GitLab patch for CVE-2026-19478 immediately on all self-hosted instances; hosted GitLab.com users are unaffected.
What this means for you — Lean IT orgs:If you self-host GitLab, update it to the latest version right away. Most teams using GitLab.com are already safe.
What this means for you — MSP:Check every self-hosted GitLab instance in your client base and push the CVE-2026-19478 patch; hosted instances need no action.
What this means for you — Researcher:Watch for public exploits and IOCs tied to CVE-2026-19478; the rapid exploitation timeline makes it a high-priority target for analysis.