GitLab disclosed and patched a critical GraphQL code-injection vulnerability, tracked as CVE-2026-19478 with a CVSS score of 9.4, in patch release 19.2.4 — and researchers at UK-based offensive security firm watchTowr say attackers began exploiting the bug in the wild within days, according to The Hacker News' weekly recap published August 24, 2026.
Unauthenticated Rewrite Of Public Projects
The flaw allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their history under specific conditions, without credentials, user interaction, or obscure configuration. GitLab's advisory recommends immediate upgrade to patched releases in the 19.2.x, 19.1.x and 19.0.x branches. The vulnerability is particularly worrying because GitLab is broadly used to host open-source dependencies and internal DevSecOps pipelines that downstream software supply chains rely on.
Part Of A Wave Of AI-Assisted Attacks
The GitLab exploitation lands the same week U.S. agencies warned that threat actors are using AI to write exploit scripts targeting Siemens S7 PLCs across water, energy and manufacturing sectors. Google separately disclosed that its Agentic Vulnerability Discovery Harness has surfaced more than 100 true-positive critical vulnerabilities in the past ten months, including CVE-2026-13242 and CVE-2026-55803 in Drupal, illustrating how defenders and attackers are now racing to weaponise AI-assisted vulnerability research.
What Enterprises Should Do Now
Security teams running self-managed GitLab should patch immediately and audit public project history for evidence of unauthorised rewrites since disclosure. This is the second high-severity GitLab flaw to draw active exploitation attention this quarter — a Jupyter-notebook diff RCE disclosed in July had proof-of-concept code circulating within days. Related U.S. cyber posture guidance was also updated this week when CISA added a Ray-framework flaw to the Known Exploited Vulnerabilities catalog.
Reporting based on coverage from The Hacker News, watchTowr and GitLab's security advisory.