Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw

Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw

First seen 22 Aug 2026, 20:19 UTC ThehackernewsButtondown 75% similarity 84.0

Article Content

Browse articles
ThreatCluster

GitLab's CVE-2026-19478, a critical code injection vulnerability with a CVSS score of 9.4, is currently under active exploitation just days after its public disclosure on August 17, 2026. Attackers are leveraging this flaw to execute unauthorized code, posing a significant risk to organizations using GitLab. Additionally, a severe vulnerability in Microsoft Entra ID, rated CVSS 10.0, allows remote code execution, necessitating immediate patch verification. The threat landscape is further complicated by supply chain attacks targeting Rust and npm packages, indicating a persistent focus on developer environments. Security teams are urged to address newly identified evasion techniques, including the misuse of Microsoft Defender's driver. The situation underscores the rapid weaponization of vulnerabilities in software development life cycles (SDLC).

Key Points: • CVE-2026-19478 is actively exploited, allowing unauthorized code execution in GitLab. • Microsoft's Entra ID vulnerability (CVSS 10.0) enables remote code execution and requires urgent patching. • Recent supply chain attacks target Rust and npm packages, highlighting ongoing threats to developer environments.

ThreatCluster AI How this analysis works

Timeline

2026-08-17
CVE-2026-19478 published
GitLab disclosed a critical code injection vulnerability with a CVSS score of 9.4.
Buttondown
2026-08-18
First public PoC released
A proof of concept for CVE-2026-19478 was made publicly available, facilitating exploitation.
Thehackernews
2026-08-22
Active exploitation reported
Researchers confirmed active exploitation of CVE-2026-19478 within days of its disclosure.
Buttondown
2026-08-22
Microsoft Entra ID flaw patched
Microsoft released patches for a critical vulnerability in Entra ID that allows remote code execution.
Buttondown

Community

Browse all →