# GitLab flaw sees exploitation attempts days after patch

_Published Thursday, August 20, 2026 at 4:17 AM EDT · Security · Developing · Tier 1 — Major_

![GitLab flaw sees exploitation attempts days after patch — Primary](https://www.securityweek.com/wp-content/uploads/2026/06/GitLab.jpeg)

Threat actors began attempting to exploit a critical GitLab code-injection flaw roughly two days after its public disclosure, according to WatchTowr's honeypot network. GitLab patched CVE-2026-19478, rated 9.4, on August 17 in specified Community and Enterprise Edition releases. The company said the defect could, under certain conditions, let an unauthenticated remote user modify or delete public projects and user data through a GraphQL directive. WatchTowr advised self-managed users to update and inspect web logs for requests containing "@gl_introduced."

## Sources

- [SecurityWeek](https://www.securityweek.com/critical-gitlab-flaw-exploited-shortly-after-disclosure/)

---
Canonical: https://techandbusiness.org/newswire/UDkWqtEEHJPh2xHkjNaH_k
Published: 2026-08-20T08:17:58.502Z
Story chronology: 2026-08-20T07:48:24.000Z
Retrieved: 2026-10-04T21:08:27.248Z
Publisher: Tech & Business (techandbusiness.org)
