GitLab released security updates for Community Edition and Enterprise Edition, shipping versions 19.2.1, 19.1.3, and 19.0.5 to fix 13 vulnerabilities and urging self-managed customers to upgrade immediately. GitLab said GitLab.com is already patched and GitLab Dedicated customers do not need to take action. The most severe issue, CVE-2026-6267, affects internal request handling in GitLab Workhorse and could let an authenticated user with the Developer role access unauthorized information because of insufficient access controls; affected versions span 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
A new CVE entry, CVE-2026-12436, was received on July 29, 2026 for a GitLab CE/EE vulnerability that could let an authenticated user modify another user's CI/CD configuration under certain conditions. The issue affects versions 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1.
On July 29, 2026, GitLab released security patch versions 19.2.1, 19.1.3, and 19.0.5 for GitLab CE/EE to fix 13 vulnerabilities, including high-severity issues involving information exposure, CI/CD pipeline manipulation, and denial of service. GitLab said GitLab.com was already patched, GitLab Dedicated customers did not need to act, and urged self-managed customers to upgrade immediately.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
cert.ug
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcedocs.gitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.