Skip to content
Critical Vulnerabilities Discovered in GitLab: Immediate Action Required

Critical Vulnerabilities Discovered in GitLab: Immediate Action Required

First seen 27 Mar 2026, 12:15 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 28, 2026 at 11:14 UTC
  • GitLab vulnerabilities allow unauthorized actions and account takeovers.
  • Four high severity CVEs require immediate patching to prevent exploitation.
  • No active exploitation reported yet, but risk remains significant.

GitLab has disclosed multiple high severity vulnerabilities affecting both Community and Enterprise Editions, necessitating immediate patching. The vulnerabilities include CVE-2026-2370 and CVE-2026-3857, which allow authenticated users to exploit sensitive data and unauthenticated attackers to execute actions on behalf of users. CVE-2026-2995 enables HTML injection, potentially leading to account takeovers, while CVE-2026-3988 can cause Denial of Service (DoS) by exhausting resources. The vulnerabilities were published on March 25, 2026, and organizations are urged to update to versions 18.10.1, 18.9.3, and 18.8.7. Although no active exploitation has been reported yet, the risk remains significant. The Centre for Cybersecurity Belgium emphasizes the urgency of installing updates after thorough testing. Organizations should also enhance monitoring to detect any suspicious activity related to these vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 177d ago How this analysis works

Timeline

2026-03-25
Multiple CVEs published, including CVE-2026-2370 and CVE-2026-3857.
2026-03-25
CVE-2026-3988 published
2026-03-25
CVE-2026-2995 published
2026-03-25
CVE-2026-2726 published
2026-03-27
GitLab issues urgent patching advisory for affected versions.

More articles in this cluster (16)

Following this threat?

Track CVE-2026-2370 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed