Skip to content
Critical RCE Vulnerabilities in GitLab and Dell; Warlock Ransomware Targets SharePoint

Critical RCE Vulnerabilities in GitLab and Dell; Warlock Ransomware Targets SharePoint

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •GitLab and Dell released critical patches for RCE vulnerabilities on October 3, 2026.
  • •Warlock ransomware is exploiting SharePoint vulnerabilities against critical infrastructure.
  • •Immediate patching is essential to prevent unauthorized access and exploitation.

GitLab and Dell released critical patches for remote code execution vulnerabilities on October 3, 2026. GitLab's AI Gateway vulnerability (CVE-2026-90970) allows arbitrary command execution on self-hosted instances, with a CVSS score of 9.9. Dell's Container Storage Modules have critical flaws (CVSS 10.0) enabling unauthenticated root access on Kubernetes nodes. Both companies urge immediate patching to prevent exploitation. Additionally, the Warlock ransomware group is actively exploiting SharePoint vulnerabilities to target water utilities, telecom operators, and government bodies. A China-linked threat actor has deployed the Antino backdoor via Outlook and OneDrive against government organizations in Asia. Organizations are advised to audit their systems for unauthorized access and apply the latest patches promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-11
CVE-2026-85706 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2026-10-02
GitLab CVE-2026-90970 published
GitLab disclosed a critical vulnerability in its AI Gateway service allowing arbitrary command execution.
Defendwork
2026-10-03
Dell Container Storage Modules vulnerabilities patched
Dell released updates for critical flaws in Container Storage Modules enabling unauthenticated root access.
Defendwork
2026-10-03
Warlock ransomware exploits SharePoint
Warlock ransomware is actively exploiting SharePoint vulnerabilities targeting various sectors including water utilities and government bodies.
Defendwork

More articles in this cluster (3)

Following this threat?

Track Warlock, Antino and Dell in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems are affected by the GitLab vulnerability?
The GitLab AI Gateway service on self-hosted instances is affected by CVE-2026-90970.
What is the CVSS score for the Dell vulnerabilities?
The Dell Container Storage Modules vulnerabilities have a CVSS score of 10.0, indicating critical severity.
How can organizations protect themselves?
Organizations should immediately apply the latest patches from GitLab and Dell and audit their systems for unauthorized access.