Skip to content

security_identifier

CVE-2026-19478

Critical GitLab GraphQL directive flaw, CVSS 9.4, allowing unauthenticated remote modification or deletion of public projects and user data under certain conditions.

Current stories

security7 publishers

GitLab's 9.4 GraphQL bug went from patch to in-the-wild traffic in about two days

WatchTowr reproduced CVE-2026-19478 from the advisory and patch alone, then caught the first exploitation attempts on its honeypots. Self-managed owners do not get a week to schedule this.

Perspective Coverage

7 publishers
Builder
Builder 29%
Operator
Operator 62%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+20
Incentives65
Confidence70
security13 publishers

CISA sets a September 13 deadline for the MikroTrick RouterOS chain

Federal agencies now have three separate patch deadlines inside twelve days. The lowest-scoring pair of the five flaws added to KEV is the one with a documented 24-day intrusion campaign behind it.

Perspective Coverage

13 publishers
Builder
Builder 21%
Operator
Operator 76%
Investor
Investor 3%

Reality

Evidence68
Adoption
Insufficient
Hype gap+15
Incentives50
Confidence66