44 CVEs published in the last four months and 8 stories. Exploited flaws first.

This week's cybersecurity landscape features AI-powered attacks targeting industrial control systems, a critical vulnerability in GitLab being actively exploited, and the discovery of trojanized npm packages delivering a sophisticated Linux backdoor. Additionally, researchers revealed a method to exploit expired credit cards for contactless payments, and several other vulnerabilities across various software platforms were highlighted.

GitLab has released an emergency patch for a critical vulnerability in its GraphQL API that allows unauthenticated attackers to modify or delete public projects and user data. Researchers from WatchTowr discovered the flaw, tracked as CVE-2026-19478, which has a CVSS score of 9.4 and is reportedly under active exploitation. The vulnerability affects self-managed installations, and users are urged to upgrade to specific patched versions, as older branches will not receive direct fixes.

GitLab's latest update, version 19.3, enhances security and control for enterprises scaling agentic software development. Key features include running GitLab Duo Agent Platform within dedicated single-tenant environments, allowing custom model integration, and keeping AI data within existing security boundaries. The release also introduces improved secrets management, bulk SAST false positive detection, and a Flow Creator Agent for simplified automation.

A critical code injection vulnerability in GitLab, identified as CVE-2026-19478, is being actively exploited shortly after its public disclosure. The flaw enables unauthenticated attackers to alter or delete public projects and their data under specific circumstances.

CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data. The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek.

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.1

The security defect allows unauthenticated attackers to modify or delete user data and public projects. The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek.

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on