Výsledky hledání

výrobce: GitLab× v celém archivu zrušit filtry

43 karet z 67 položek CZ · EN/orig

1

SPOJENO PŘES CVE GitLab opravil kritickou zranitelnost umožňující čtení citlivých dat

GitLab vyzval uživatele k okamžité aktualizaci serverů kvůli kritické zranitelnosti CVE-2026-85706 typu path traversal. Chyba v rozhraní API pro revize kódu v repozitářích umožňuje za určitých podmínek neověřenému útočníkovi číst libovolná data ze zranitelného serveru, včetně přihlašovacích údajů a dalších citlivých informací. Společnost watchTowr již zaznamenala pokusy o vyhledávání neaktualizovaných serverů dostupných z internetu. GitLab zranitelnost opravil ve verzích 19.3.2, 19.2.6 a 19.1 a…

KEV ✓ EPSS 0.15 CVE-2026-85706 GitLab veřejná správa CZ NL CA US

tg: zneužíváno tg: zranitelnost tg: regulace tg: novinka v produktu

· CSIRT.CZ (CZ.NIC) · GitLab opravil kritickou zranitelnost umožňující čtení citlivých dat · NCSC-NL · NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions · Cyber Centre Kanada · GitLab security advisory (AV26-917) · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability (CVE-2026-85706)

3

14th September – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a collection containing millions of identity documents, including driver’s licenses, associated with the…

KEV ✓ EPSS 0.94 CVSS 10.0 CVE-2026-67276 CVE-2026-72898 CVE-2026-81963 CVE-2026-85046 CVE-2026-85706 CVE-2026-85880 CVE-2026-86060 Microsoft GitLab MikroTik Anthropic IL

tg: incident tg: zranitelnost tg: přehled tp: malware tp: únik dat tp: AI

· Check Point Research · 14th September – Threat Intelligence Report

SPOJENO PŘES CVE CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions.On September…

KEV ✓ EPSS 0.15 CVSS 10.0 CVE-2026-85706 CVE-2026-87719 GitLab US SE

tg: zneužíváno tg: zranitelnost tg: novinka v produktu

· Rapid7 · CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild · CERT-SE · GitLab rättar kritiska sårbarheter

1

GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-85706, CVE-2026-87719, CVE-2026-88765, CVE-2026-79708, CVE-2026-78252, CVE-2026-13210, CVE-2025-14871, CVE-2026-1168, CVE-2024-11222, CVE-2026-12910, CVE-2026-82837, CVE-2026-19619, CVE-2026-86341, CVE-2026-86340, CVE-2026-7514, CVE-2026-8030, CVE-2026-16794, CVE-2026-3855, Summary: On September 10, 2026, we released versions 19.3.2, 19.2.6, 19.1.8 for GitLab Community Edition (CE)…

CVSS 10.0 GitLab FI

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

4

VAROVANIE: Kritické zraniteľnosti GITLAB CE a EE

Národné centrum kybernetickej bezpečnosti (NCKB) NBÚ varuje pred kritickými zraniteľnosťami v produktoch GitLab Community Edition (CE) a GitLab Enterprise Edition (EE). Uvedené zraniteľnosti možno zneužiť na získanie neoprávneného prístupu k citlivým údajom a úplné narušenie dôvernosti, integrity a dostupnosti systémov. Vývojári GitLab 10. septembra 2026 vydali bezpečnostné aktualizácie, ktoré opravujú až 18 zraniteľností, z ktorých 2 sú... The post VAROVANIE: Kritické zraniteľnosti GITLAB CE a…

GitLab SK

tg: zranitelnost

· SK-CERT (NBÚ SR) · VAROVANIE: Kritické zraniteľnosti GITLAB CE a EE

SPOJENO PŘES CVE Risolte vulnerabilità in GitLab CE/EE

Aggiornamenti di sicurezza rilasciati per GitLab, nota piattaforma per la gestione del ciclo di sviluppo software e della collaborazione sui progetti, sanano alcune vulnerabilità, di cui 2 con gravità "critica" e 6 con gravità "alta"

KEV ✓ EPSS 0.15 CVSS 10.0 CVE-2025-14871 CVE-2026-1168 CVE-2026-13210 CVE-2026-78252 CVE-2026-79708 CVE-2026-85706 CVE-2026-87719 CVE-2026-88765 GitLab IT US

tg: zranitelnost tg: novinka v produktu

· CSIRT Itálie (ACN) · Risolte vulnerabilità in GitLab CE/EE · GitLab Security · GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

1

1

SPOJENO PŘES CVE GitLab Patch Release: 19.3.1, 19.2.5, 19.1.7

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.3, CVEs: CVE-2026-18252, CVE-2026-77801, CVE-2025-10903, CVE-2026-3035, CVE-2026-4398, CVE-2026-15387, CVE-2026-7487, Summary: On August 26, 2026, we released versions 19.3.1, 19.2.5, 19.1.7 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these…

EPSS 0.00 CVSS 8.7 CVE-2025-10903 CVE-2026-15387 CVE-2026-18252 CVE-2026-3035 CVE-2026-4398 CVE-2026-7487 CVE-2026-77801 GitLab FI FR US

· NCSC-FI · GitLab Patch Release: 19.3.1, 19.2.5, 19.1.7 · CERT-FR – avis · Multiples vulnérabilités dans GitLab (26 août 2026) · GitLab Security · GitLab Patch Release: 19.3.1, 19.2.5, 19.1.7

1

Risolte vulnerabilità su GitLab CE/EE

Aggiornamenti di sicurezza GitLab sanano alcune vulnerabilità, di cui una con gravità "alta", presente in GitLab Enterprise Edition (EE), nota piattaforma per la gestione del ciclo di sviluppo del software. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a un utente autenticato con privilegi di sviluppatore di eseguire codice arbitrario sui sistemi interessati.

EPSS 0.00 CVE-2026-18252 GitLab IT

· CSIRT Itálie (ACN) · Risolte vulnerabilità su GitLab CE/EE

2

24th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people – roughly two-thirds of the country’s population – as well as 200,000 organizations. The stolen data included identification numbers, license plates, payment amounts, dates and addresses. Attackers reportedly exploited a…

KEV ✓ · ransomware EPSS 0.41 CVSS 10.0 CVE-2026-12569 CVE-2026-19478 CVE-2026-19489 CVE-2026-19490 Snowflake Siemens GitLab Cisco zdravotnictví výroba a průmysl energetika vodárenství IL

· Check Point Research · 24th August – Threat Intelligence Report

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.5, CVEs: CVE-2026-10053, Summary: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.

EPSS 0.01 CVSS 8.5 CVE-2026-10053 GitLab FI

· NCSC-FI · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab

1

Is Cyber missing the Marque?

Welcome to this week’s edition of the Threat Source newsletter. Hello friend. I’m Mick. This is my first Threat Source newsletter, so I should probably introduce myself before I start telling you all the things I think you should be paying attention to. With assistance from an unnamed LLM, my bio reads like this: Mick Baccio is a globally recognized security strategist with a career spanning offensive operations, threat intelligence, and national-level incident response. He currently advises…

GitLab Apple Microsoft veřejná správa obrana US

· Cisco Talos · Is Cyber missing the Marque?

1

SPOJENO PŘES CVE GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.4, CVEs: CVE-2026-19650, CVE-2026-19478, Summary: CVE-2026-19478 9.4 GitLab has remediated an issue that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive. CVE-2026-19650 7.1 GitLab has remediated an issue that under certain conditions could have allowed an unauthenticated user to execute mutations via GET…

EPSS 0.06 CVSS 9.4 CVE-2026-19478 CVE-2026-19650 GitLab FI IT FR US

· NCSC-FI · GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11 · CSIRT Itálie (ACN) · Rilevate vulnerabilità in GitLab · CERT-FR – avis · Multiples vulnérabilités dans GitLab (18 août 2026) · GitLab Security · GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11

2

GitLab security advisory (AV26-827)

Serial Number: AV26-827Date: August 18, 2026 As of August 17, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 18.11.11 Prior to 19.0.8 Prior to 19.1.6 Prior to 19.2.4 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11 | GitLab Docs GitLab release notes | GitLab Docs

GitLab CA

· Cyber Centre Kanada · GitLab security advisory (AV26-827)

NCSC-2026-0303 [1.00] [M/H] Kwetsbaarheden verholpen in GitLab door GitLab Inc.

GitLab Inc. heeft kwetsbaarheden verholpen in GitLab Community Edition (CE) en Enterprise Edition (EE). De kwetsbaarheden bevinden zich in de GraphQL-implementatie van GitLab. Een eerste kwetsbaarheid maakte het mogelijk voor niet-geauthenticeerde gebruikers om via een GraphQL-directive ongeautoriseerde wijzigingen of verwijderingen uit te voeren op publieke projecten en gebruikersdata. Een tweede kwetsbaarheid stelde niet-geauthenticeerde gebruikers in staat om mutaties uit te voeren via GET…

GitLab NL

· NCSC-NL · NCSC-2026-0303 [1.00] [M/H] Kwetsbaarheden verholpen in GitLab door GitLab Inc.

4

GitLab security advisory (AV26-814)

Serial Number: AV26-814Date: August 13, 2026 As of August 12, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 19.0.6 Prior to 19.1.4 Prior to 19.2.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. GitLab Patch Release: 19.2.2, 19.1.4, 19.0.6 | GitLab Docs

GitLab CA

· Cyber Centre Kanada · GitLab security advisory (AV26-814)

NCSC-2026-0297 [1.00] [M/H] Kwetsbaarheden verholpen in GitLab Enterprise Edition en Community Edition

GitLab heeft meerdere kwetsbaarheden verholpen in GitLab Enterprise Edition (EE) en Community Edition (CE) versies variërend van 12.0 tot en met 19.2.2. De kwetsbaarheden betreffen verschillende aspecten van GitLab, waaronder onjuiste privilege-toewijzing waarbij gebruikers met een pending lidmaatschapsstatus onbedoeld permissies konden erven van custom rollen. Verder zijn er problemen met ontbrekende autorisatiecontroles op API-endpoints, waardoor gebruikers met ontwikkelaarsrollen toegang…

GitLab NL

· NCSC-NL · NCSC-2026-0297 [1.00] [M/H] Kwetsbaarheden verholpen in GitLab Enterprise Edition en Community Edition

Risolte vulnerabilità su GitLab CE/EE

Rilasciati aggiornamenti di sicurezza che risolvono 13 vulnerabilità, di cui 6 con gravità “alta”, in GitLab Community Edition (CE) ed Enterprise Edition (EE). Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato remoto di elevare i propri privilegi, accedere a informazioni sensibili e/o eludere meccanismi di sicurezza sui sistemi interessati.

EPSS 0.00 CVE-2026-15216 CVE-2026-15217 CVE-2026-15423 CVE-2026-16494 CVE-2026-16627 CVE-2026-19228 GitLab IT

· CSIRT Itálie (ACN) · Risolte vulnerabilità su GitLab CE/EE

Multiples vulnérabilités dans GitLab (13 août 2026)

De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

EPSS 0.00 CVE-2025-9486 CVE-2026-15216 CVE-2026-15217 CVE-2026-15423 CVE-2026-16494 CVE-2026-16627 CVE-2026-18244 CVE-2026-18433 CVE-2026-19228 CVE-2026-4879 CVE-2026-6821 CVE-2026-7427 CVE-2026-8667 GitLab FR

· CERT-FR – avis · Multiples vulnérabilités dans GitLab (13 août 2026)

1

SPOJENO PŘES CVE GitLab Patch Release: 19.2.2, 19.1.4, 19.0.6

On August 12, 2026, we released versions 19.2.2, 19.1.4, 19.0.6 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch…

EPSS 0.01 CVSS 8.7 CVE-2026-10053 CVE-2026-15216 CVE-2026-15217 CVE-2026-15423 CVE-2026-16494 CVE-2026-16627 CVE-2026-19228 CVE-2026-6821 CVE-2026-7427 GitLab US

· GitLab Security · GitLab Patch Release: 19.2.2, 19.1.4, 19.0.6

2

GitLab Patch Release: 18.11.9

On August 6, 2026, we released versions 18.11.9 for GitLab Community Edition and Enterprise Edition. These versions resolve a number of regressions and bugs. This patch release does not include any security fixes. GitLab Community Edition and Enterprise Edition 18.11.9 We have pulled the omnibus install of 18.11.8 and replaced it with 18.11.9. A bug was found in the deprecation code that enabled Mattermost incorrectly. If you have a local cache of our omnibus package, you will want to remove 18…

GitLab US

· GitLab Security · GitLab Patch Release: 18.11.9

GitLab Patch Release: 18.11.9

On August 6, 2026, we released versions 18.11.9 for GitLab Community Edition and Enterprise Edition. These versions resolve a number of regressions and bugs. This patch release does not include any security fixes. GitLab Community Edition and Enterprise Edition 18.11.9 We have pulled the omnibus install of 18.11.8 and replaced it with 18.11.9. A bug was found in the deprecation code that enabled Mattermost incorrectly. If you have a local cache of our omnibus package, you will want to remove 18…

GitLab US

· GitLab Security · GitLab Patch Release: 18.11.9

1

SPOJENO PŘES CVE GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5

On July 29, 2026, we released versions 19.2.1, 19.1.3, 19.0.5 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch…

EPSS 0.00 CVSS 8.5 CVE-2026-12436 CVE-2026-13113 CVE-2026-14341 CVE-2026-15077 CVE-2026-15831 CVE-2026-15975 CVE-2026-16553 CVE-2026-3093 CVE-2026-6267 CVE-2026-6336 GitLab US

· GitLab Security · GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5

1

SPOJENO PŘES CVE GitLab Patch Release: 19.1.2, 19.0.4, 18.11.7

On July 8, 2026, we released versions 19.1.2, 19.0.4, 18.11.7 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch…

EPSS 0.00 CVSS 8.7 CVE-2025-12506 CVE-2026-11827 CVE-2026-13151 CVE-2026-13320 CVE-2026-6352 CVE-2026-6896 CVE-2026-7492 CVE-2026-8472 GitLab US

· GitLab Security · GitLab Patch Release: 19.1.2, 19.0.4, 18.11.7

2

GitLab Patch Release: 18.8.11

On July 1, 2026, we released version 18.8.11 for GitLab Community Edition and Enterprise Edition. These versions resolve regressions and bugs. This patch release does not include any security fixes. When database load balancing is in use, database connections may not be returned to the pool as a result of a regression caused by the upgrade to Rails 7.2. We are making an out-of-band patch release to ensure stability for customers upgrading to the required stop of GitLab 18.8. GitLab Community…

GitLab US

· GitLab Security · GitLab Patch Release: 18.8.11

GitLab Patch Release: 18.8.11

On July 1, 2026, we released version 18.8.11 for GitLab Community Edition and Enterprise Edition. These versions resolve regressions and bugs. This patch release does not include any security fixes. When database load balancing is in use, database connections may not be returned to the pool as a result of a regression caused by the upgrade to Rails 7.2. We are making an out-of-band patch release to ensure stability for customers upgrading to the required stop of GitLab 18.8. GitLab Community…

GitLab US

· GitLab Security · GitLab Patch Release: 18.8.11

1

SPOJENO PŘES CVE GitLab Patch Release: 19.1.1, 19.0.3, 18.11.6

On June 24, 2026, we released versions 19.1.1, 19.0.3, 18.11.6 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch…

EPSS 0.01 CVSS 8.7 CVE-2026-10086 CVE-2026-10712 CVE-2026-11379 CVE-2026-12053 CVE-2026-1606 CVE-2026-2238 CVE-2026-5309 CVE-2026-5796 CVE-2026-5952 CVE-2026-8330 GitLab US

· GitLab Security · GitLab Patch Release: 19.1.1, 19.0.3, 18.11.6

1

SPOJENO PŘES CVE GitLab Patch Release: 19.0.2, 18.11.5, 18.10.8

On June 10, 2026, we released versions 19.0.2, 18.11.5, 18.10.8 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch…

EPSS 0.00 CVSS 8.7 CVE-2026-10087 CVE-2026-10733 CVE-2026-1500 CVE-2026-6269 CVE-2026-6277 CVE-2026-6552 CVE-2026-6976 CVE-2026-7250 CVE-2026-8589 CVE-2026-9204 GitLab US

· GitLab Security · GitLab Patch Release: 19.0.2, 18.11.5, 18.10.8

3

SPOJENO PŘES CVE GitLab Patch Release: 19.0.1, 18.11.4, 18.10.7

On May 27, 2026, we released versions 19.0.1, 18.11.4, 18.10.7 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch…

EPSS 0.00 CVSS 8.2 CVE-2026-1402 CVE-2026-2601 CVE-2026-2710 CVE-2026-4868 CVE-2026-5296 CVE-2026-6713 CVE-2026-8716 GitLab US

· GitLab Security · GitLab Patch Release: 19.0.1, 18.11.4, 18.10.7

GitLab Patch Release: 18.9.8, 18.8.10, 18.7.7, 18.6.8, 18.5.7

Today, we are releasing versions 18.9.8, 18.8.10, 18.7.7, 18.6.8, and 18.5.7 for GitLab Community Edition and Enterprise Edition. These versions resolve a number of regressions and bugs. This patch release does not include any security fixes. This patch release addresses a regression introduced in GitLab 18.4 where issues appeared duplicated in Epic swimlane board views — showing under both their direct parent epic and the grandparent epic — even when no filter was applied. This caused boards…

GitLab US

· GitLab Security · GitLab Patch Release: 18.9.8, 18.8.10, 18.7.7, 18.6.8, 18.5.7

GitLab Patch Release: 18.9.8, 18.8.10, 18.7.7, 18.6.8, 18.5.7

Today, we are releasing versions 18.9.8, 18.8.10, 18.7.7, 18.6.8, and 18.5.7 for GitLab Community Edition and Enterprise Edition. These versions resolve a number of regressions and bugs. This patch release does not include any security fixes. This patch release addresses a regression introduced in GitLab 18.4 where issues appeared duplicated in Epic swimlane board views — showing under both their direct parent epic and the grandparent epic — even when no filter was applied. This caused boards…

GitLab US

· GitLab Security · GitLab Patch Release: 18.9.8, 18.8.10, 18.7.7, 18.6.8, 18.5.7

1

SPOJENO PŘES CVE GitLab Patch Release: 18.11.3, 18.10.6, 18.9.7

On May 13, 2026, we released versions 18.11.3, 18.10.6, 18.9.7 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch…

EPSS 0.00 CVSS 8.7 CVE-2025-14869 CVE-2025-14870 CVE-2026-1322 CVE-2026-1659 CVE-2026-5297 CVE-2026-6073 CVE-2026-7377 CVE-2026-7481 GitLab US

· GitLab Security · GitLab Patch Release: 18.11.3, 18.10.6, 18.9.7

3

CI/CD pipeline abuse: the problem no one is watching

Preamble In 2025 and 2026, we watched a pattern play out across the industry. Attackers stopped going after production servers directly and started targeting the automation that deploys to them. Compromised developer credentials, a modified workflow file, and suddenly every secret in a CI/CD environment is streaming to an attacker-controlled endpoint. We saw this play out across incidents involving major open-source projects, Fortune 500 companies, and critical infrastructure tooling. The…

GitHub GitLab Microsoft US

tg: rozbor tg: novinka v produktu tp: dodavatelský řetězec tp: AI tp: identita

· Elastic Security · CI/CD pipeline abuse: the problem no one is watching

GitLab Patch Release: 18.11.2, 18.10.5

On April 29, 2026, we released versions 18.11.2 and 18.10.5 for GitLab Community Edition and Enterprise Edition. These out-of-band patch releases fix an observability gap to ensure we continue to meet our disaster recovery RTO/RPO commitments for our GitLab Dedicated customers. These versions also resolve a number of regressions and bugs. This patch release does not include any security fixes. GitLab Community Edition and Enterprise Edition 18.11.2 Revert “Merge branch ‘ia-refactor-role…

GitLab US

· GitLab Security · GitLab Patch Release: 18.11.2, 18.10.5

GitLab Patch Release: 18.11.2, 18.10.5

On April 29, 2026, we released versions 18.11.2 and 18.10.5 for GitLab Community Edition and Enterprise Edition. These out-of-band patch releases fix an observability gap to ensure we continue to meet our disaster recovery RTO/RPO commitments for our GitLab Dedicated customers. These versions also resolve a number of regressions and bugs. This patch release does not include any security fixes. GitLab Community Edition and Enterprise Edition 18.11.2 Revert “Merge branch ‘ia-refactor-role…

GitLab US

· GitLab Security · GitLab Patch Release: 18.11.2, 18.10.5

1

SPOJENO PŘES CVE GitLab Patch Release: 18.11.1, 18.10.4, 18.9.6

On April 22, 2026, we released versions 18.11.1, 18.10.4, 18.9.6 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch…

EPSS 0.00 CVSS 8.1 CVE-2025-0186 CVE-2025-3922 CVE-2025-6016 CVE-2026-1660 CVE-2026-3254 CVE-2026-4922 CVE-2026-5262 CVE-2026-5377 CVE-2026-5816 CVE-2026-6515 GitLab US

· GitLab Security · GitLab Patch Release: 18.11.1, 18.10.4, 18.9.6

1

SPOJENO PŘES CVE GitLab Patch Release: 18.10.3, 18.9.5, 18.8.9

On April 8, 2026, we released versions 18.10.3, 18.9.5, 18.8.9 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch…

EPSS 0.01 CVSS 8.5 CVE-2025-12664 CVE-2025-9484 CVE-2026-1092 CVE-2026-1101 CVE-2026-1403 CVE-2026-1516 CVE-2026-1752 CVE-2026-2104 CVE-2026-2619 CVE-2026-4332 CVE-2026-5173 GitLab US

· GitLab Security · GitLab Patch Release: 18.10.3, 18.9.5, 18.8.9

1

SPOJENO PŘES CVE GitLab Patch Release: 18.10.1, 18.9.3, 18.8.7

On March 25, 2026, we released versions 18.10.1, 18.9.3, 18.8.7 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch…

EPSS 0.00 CVSS 8.1 CVE-2025-13078 CVE-2025-13436 CVE-2026-1724 CVE-2026-2370 CVE-2026-2726 CVE-2026-2745 CVE-2026-2973 CVE-2026-2995 CVE-2026-3857 CVE-2026-3988 GitLab US

· GitLab Security · GitLab Patch Release: 18.10.1, 18.9.3, 18.8.7

1

SPOJENO PŘES CVE GitLab Patch Release: 18.9.2, 18.8.6, 18.7.6

On March 11, 2026, we released versions 18.9.2, 18.8.6, 18.7.6 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch…

EPSS 0.01 CVSS 8.7 CVE-2025-12555 CVE-2025-12576 CVE-2025-13690 CVE-2025-13929 CVE-2025-14513 CVE-2026-0602 CVE-2026-1069 CVE-2026-1090 CVE-2026-1732 CVE-2026-3848 GitLab US

· GitLab Security · GitLab Patch Release: 18.9.2, 18.8.6, 18.7.6

1

SPOJENO PŘES CVE GitLab Patch Release: 18.9.1, 18.8.5, 18.7.5

On February 25, 2026, we released versions 18.9.1, 18.8.5, 18.7.5 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of…

EPSS 0.00 CVSS 8.0 CVE-2025-14103 CVE-2025-14511 CVE-2025-3525 CVE-2026-0752 CVE-2026-1388 CVE-2026-1662 CVE-2026-1725 CVE-2026-1747 CVE-2026-2845 GitLab US

· GitLab Security · GitLab Patch Release: 18.9.1, 18.8.5, 18.7.5