Ccb.Belgium.Be Critical Vulnerabilities Discovered in GitLab: Immediate Action Required
Article Content
- •GitLab vulnerabilities allow unauthorized actions and account takeovers.
- •Four high severity CVEs require immediate patching to prevent exploitation.
- •No active exploitation reported yet, but risk remains significant.
GitLab has disclosed multiple high severity vulnerabilities affecting both Community and Enterprise Editions, necessitating immediate patching. The vulnerabilities include CVE-2026-2370 and CVE-2026-3857, which allow authenticated users to exploit sensitive data and unauthenticated attackers to execute actions on behalf of users. CVE-2026-2995 enables HTML injection, potentially leading to account takeovers, while CVE-2026-3988 can cause Denial of Service (DoS) by exhausting resources. The vulnerabilities were published on March 25, 2026, and organizations are urged to update to versions 18.10.1, 18.9.3, and 18.8.7. Although no active exploitation has been reported yet, the risk remains significant. The Centre for Cybersecurity Belgium emphasizes the urgency of installing updates after thorough testing. Organizations should also enhance monitoring to detect any suspicious activity related to these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (16)
Following this threat?
Track CVE-2026-2370 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…