Cyber security GitLab CVE-2026-19478 exploited within days of patch release GitLab CVE-2026-19478, a CVSS 9.4 GraphQL injection flaw, lets unauthenticated attackers delete repos and forge merges. It is already exploited in the wild. Lars Cornelissen · Aug 23, 2026