GitLab CE/EE security update for CVE-2026-19478 and CVE-2026-19650
Security Patch Release
Summary
Hide ▲
Show ▼
GitLab released out-of-band security updates on August 17, 2026 for GitLab CE/EE to fix CVE-2026-19478, a critical GraphQL issue that could let an unauthenticated attacker remotely modify or delete public projects and user data. The same release also patched CVE-2026-19650 in the GraphQL multiplex query handler. GitLab.com and GitLab Dedicated were already patched. Self-managed installations need to move to 19.2.4, 19.1.6, 19.0.8, or 18.11.11.
Related Happenings
N-able security patch release for CVE-2026-18577
Security Patch Release
H score46
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
N-able security patch release for CVE-2026-18577
Security Patch ReleaseAbout this happening: N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
Rails maintainers security patch release for CVE-2026-66066
Security Patch Release
H score40
First: 01.08.2026 17:20
Last: 01.08.2026 17:20
Sources 1
About this happening:
Rails published an advisory and version guidance for CVE-2026-66066, a critical Active Storage flaw affecting specific release lines and requiring upgrades. The patch...
Rails maintainers security patch release for CVE-2026-66066
Security Patch ReleaseAbout this happening: Rails published an advisory and version guidance for CVE-2026-66066, a critical Active Storage flaw affecting specific release lines and requiring upgrades. The patch...
OpenWrt security patch release for CVE-2026-53921
Security Patch Release
H score37
First: 28.07.2026 15:56
Last: 28.07.2026 15:56
Sources 1
About this happening:
OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
OpenWrt security patch release for CVE-2026-53921
Security Patch ReleaseAbout this happening: OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
H score55
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch ReleaseAbout this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch Release
H score29
First: 14.07.2026 16:48
Last: 14.07.2026 16:48
Sources 1
About this happening:
RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch ReleaseAbout this happening: RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
Timeline
-
21.08.2026 10:04 1 articles · 10d ago
watchTowr observes active exploitation of GitLab CVE-2026-19478
Exploitation ObservedwatchTowr observed in-the-wild exploitation of GitLab CVE-2026-19478 against its honeypot network and said it could reproduce the flaw within minutes of disclosure. GitLab said the issue could be exploited via a GraphQL directive, and defenders were told to hunt web logs for requests containing '@gl_introduced' and to restrict unauthenticated access to "/api/graphql" if patching is not immediately possible.
Show sources
- GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure — thehackernews.com — 21.08.2026 10:04
-
18.08.2026 00:03 3 articles · 13d ago
GitLab releases out-of-band fixes for CVE-2026-19478 and CVE-2026-19650
Mitigation Patch UpdateGitLab released out-of-band security updates for GitLab Community Edition (CE) and Enterprise Edition (EE) on August 17, 2026 to fix CVE-2026-19478, a Critical 9.4 GraphQL directive flaw that could let an unauthenticated attacker remotely modify or delete public projects and user data, and CVE-2026-19650, a High 7.1 CSRF weakness in the GraphQL multiplex query handler. GitLab.com and GitLab Dedicated were already running the patched version, while self-managed installations needed GitLab 19.2.4, 19.1.6, 19.0.8, or 18.11.11.
Show sources
- Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects — thehackernews.com — 18.08.2026 00:03
- Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects — thehackernews.com — 18.08.2026 00:03
- GitLab Patches Critical Code Injection Vulnerability — www.securityweek.com — 18.08.2026 11:51