type: incident ยท created: 2026-08-21 ยท updated: 2026-08-22 ยท tags: [incident, breach] ยท confidence: high ยท affected_sectors: [sector-technology] ยท au_impact: false
A newly disclosed GitLab flaw, CVE-2026-19478 (CVSS 9.4), is under active exploitation within days of disclosure, according to preemptive exposure-management firm watchTowr, which reproduced it within minutes and observed in-the-wild exploitation against its honeypot network. The unauthenticated code-injection flaw lets an attacker modify or delete publicly accessible GitLab projects and rewrite data; watchTowr notes attackers could delete repositories, forge merge records and ban maintainers. GitLab patched it in 19.2.4, 19.1.6, 19.0.8 and 18.11.11; operators of internet-facing instances should upgrade immediately or restrict unauthorised access to /api/graphql.