Skip to content
Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw

Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw

First seen 22 Aug 2026, 20:19 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 23, 2026 at 20:17 UTC
  • •CVE-2026-19478 is actively exploited, allowing unauthorized code execution in GitLab.
  • •Microsoft's Entra ID vulnerability (CVSS 10.0) enables remote code execution and requires urgent patching.
  • •Recent supply chain attacks target Rust and npm packages, highlighting ongoing threats to developer environments.

GitLab's CVE-2026-19478, a critical code injection vulnerability with a CVSS score of 9.4, is currently under active exploitation just days after its public disclosure on August 17, 2026. Attackers are leveraging this flaw to execute unauthorized code, posing a significant risk to organizations using GitLab. Additionally, a severe vulnerability in Microsoft Entra ID, rated CVSS 10.0, allows remote code execution, necessitating immediate patch verification. The threat landscape is further complicated by supply chain attacks targeting Rust and npm packages, indicating a persistent focus on developer environments. Security teams are urged to address newly identified evasion techniques, including the misuse of Microsoft Defender's driver. The situation underscores the rapid weaponization of vulnerabilities in software development life cycles (SDLC).

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 47d ago How this analysis works

Timeline

2026-08-17
CVE-2026-19478 published
GitLab disclosed a critical code injection vulnerability with a CVSS score of 9.4.
Buttondown
2026-08-18
First public PoC released
A proof of concept for CVE-2026-19478 was made publicly available, facilitating exploitation.
Thehackernews
2026-08-22
Active exploitation reported
Researchers confirmed active exploitation of CVE-2026-19478 within days of its disclosure.
Buttondown
2026-08-22
Microsoft Entra ID flaw patched
Microsoft released patches for a critical vulnerability in Entra ID that allows remote code execution.
Buttondown

More articles in this cluster (2)

Following this threat?

Track Emotet, Microolap and CVE-2026-19478 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed