A critical-severity vulnerability in GitLab (CVE-2026-19478) has been exploited within two days of its disclosure, allowing unauthenticated attackers to remotely modify or delete public projects and user data. The flaw, which has a CVSS score of 9.4, was patched on August 17, 2026. WatchTowr warns users to update their GitLab instances promptly and restrict access to certain endpoints to mitigate risks.
Exploiting this vulnerability could facilitate supply chain attacks by allowing attackers to forge trusted merge records. Organizations are advised to monitor logs for signs of exploitation attempts.