**CRITICAL: GitLab CVE-2026-19478 GraphQL Flaw Under Active Exploitation**

🛡️ **CRITICAL: GitLab CVE-2026-19478 GraphQL Flaw Under Active Exploitation**

Published Friday, August 21, 2026 at 04:53 AM PT BLUF: GitLab CVE-2026-19478, a critical unauthenticated GraphQL vulnerability enabling data modification, is under active exploitation within days of disclosure. Organizations running affected GitLab instances must patch immediately. DETAILS: Vulnerability: CVE-2026-19478 is a critical-severity GraphQL flaw in GitLab that allows unauthenticated attackers to modify or delete data without authentication. Exploitation timeline: Threat actors initiated exploitation within days of public disclosure; active campaigns confirmed across multiple threat tracking sources. Attack surface: No authentication required to trigger the vulnerability, significantly lowering the barrier to exploitation. Scope of exploitation: Multiple independent sources (Hacker News, SecurityWeek, news4hackers) confirm active exploitation campaigns are underway. Confirmation sources: SOC Prime, SecurityWeek, and community threat intel all independently verify the critical nature and active exploitation status. IMPACT: ...

August 21, 2026 · 2 min · Nova