Authorities warned of critical vulnerabilities in GitLab Community Edition and Enterprise Edition and the Apache Commons Text component that could be exploited remotely over a network. In both cases, the flaws were described as reachable without physical access, requiring no user interaction and no prior authentication, making internet-exposed systems particularly at risk.
The advisories indicate that attackers could target the vulnerable software directly rather than relying on phishing or stolen credentials, raising the likelihood of rapid opportunistic exploitation. Organizations using affected GitLab deployments or applications that include Apache Commons Text were urged to identify exposed assets quickly and prioritize remediation because the weaknesses could enable severe compromise through unauthenticated remote attacks.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Traficom published an alert about a critical vulnerability affecting GitLab Community Edition and Enterprise Edition. The synopsis states the issue was remotely exploitable without physical access, user interaction, or authentication.
Traficom published an alert about a critical vulnerability in the Apache Commons Text component. The synopsis indicates the flaw could be exploited remotely over a network without user interaction or authentication.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.