Critical GitLab Vulnerability Under Active Attack — Patch Immediately
Security researchers have confirmed that a critical vulnerability in GitLab, tracked as CVE-2026-19478, is being actively exploited just days after it was publicly disclosed. The flaw is particularly dangerous because it can be exploited without any authentication, meaning attackers do not need a username, password, or existing account to take advantage of it.
Once exploited, the vulnerability allows attackers to modify or delete public projects and user data stored in GitLab. For businesses that rely on GitLab to manage source code, development pipelines, or collaborative projects, this could mean lost work, corrupted repositories, or exposure of sensitive information — with potentially serious knock-on effects for software integrity and customer trust.
The speed at which this flaw moved from disclosure to active exploitation highlights a growing trend: attackers are increasingly quick to weaponise newly published vulnerabilities. Any Australian small business using GitLab, whether self-hosted or through a managed provider, should treat this as an urgent priority and apply available security updates without delay.