type: cve ยท created: 2026-08-22 ยท updated: 2026-08-22 ยท tags: [cve, zero-day, kev, supply-chain] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, finance] ยท au_impact: true
GitLab CVE-2026-19478 (CVSS 9.4): an unauthenticated code-injection vulnerability exploitable via a GraphQL directive that lets an attacker modify or delete publicly accessible GitLab projects and rewrite data. Observed under active exploitation within days of disclosure (watchTowr). Patched in GitLab 19.2.4, 19.1.6, 19.0.8 and 18.11.11.