CRITICAL: GitLab GraphQL Flaw CVE-2026-19478 Exploited in the Wild
GitLab patched CVE-2026-19478 on August 17, 2026, a CVSS 9.4 code injection flaw in the GraphQL API that lets unauthenticated attackers modify or delete public projects. watchTowr observed active exploitation within days, including repository deletion and forged merge records. Self managed instances from 18.2 through 19.2.3 should upgrade immediately.