GitLab GraphQL code injection vulnerability

A GitLab GraphQL code injection vulnerability (CVE-2026-19478, CVSS 9.4) was exploited within minutes of disclosure. What happened and how to patch now.

A GitLab GraphQL code injection vulnerability is now under active exploitation, reproduced and attacked within minutes of GitLab’s August 17, 2026 disclosure of CVE-2026-19478. The unauthenticated flaw (CVSS 9.4) lets an attacker delete public projects, forge fake fix records, or lock out maintainers on any unpatched self-managed GitLab instance. GitLab.com and GitLab Dedicated were already…

Read More

TeamCity CVE-2026-63077 RCE: Unauthenticated CI/CD Takeover

TeamCity CVE-2026-63077 RCE

TeamCity CVE-2026-63077 RCE lets an unauthenticated attacker send a single crafted request to a TeamCity On-Premises server and execute operating system commands — no login, no valid session, no user interaction. CISA added it to the Known Exploited Vulnerabilities catalog on August 5 with a three-day remediation deadline, and exploitation is now active in the…

Read More

GitLab Oj Spill RCE Exploit Goes Public

GitLab Oj Spill RCE Exploit Goes Public

The GitLab Oj Spill RCE is now public: a working exploit chain and full technical writeup were released on July 24 for a remote-code-execution flaw that GitLab quietly patched six weeks earlier, on June 10. If your self-managed GitLab instance is still on 18.10.7 or older, any developer who can push a commit can now…

Read More

The New Era of Software Supply Chain Risk

software supply chain risk

Modern businesses are now software businesses, and software supply chain risk is now a business risk, not just a developer problem. Whether you manufacture industrial components, process financial transactions, run logistics networks, or operate online storefronts, your business likely depends on ERP systems, customer portals, payment integrations, cloud workloads, APIs, automation scripts, and other layers…

Read More

Top 5 Cybersecurity News Stories March 27, 2026

News Stories March 27

News Stories March 27 reveal a clear shift: compromise paths are moving into control planes,the systems that issue trust, ship code, govern identity, and manage fleets. This week wasn’t defined by “more breaches,” but by higher leverage. Attackers aren’t forcing doors; they’re operating inside the infrastructure behind them. When the control plane is compromised, every…

Read More