Sqmagazine GitLab Issues Urgent Patch for Critical AI Gateway RCE Flaw
Article Content
- •CVE-2026-90970 is a critical RCE vulnerability with a CVSS score of 9.9.
- •The flaw allows authenticated users to execute arbitrary commands on self-hosted AI Gateways.
- •Patches are available in versions 19.2.4, 19.3.2, and 19.4.1; immediate updates are recommended.
GitLab has disclosed a critical remote code execution vulnerability, CVE-2026-90970, affecting self-hosted AI Gateways. The flaw allows authenticated users with Duo Agent Platform access to escape a prompt template sandbox and execute arbitrary commands on the gateway. GitLab released patches in versions 19.2.4, 19.3.2, and 19.4.1 on October 2, 2026, and strongly recommends that self-managed customers update immediately. The vulnerability has a CVSS score of 9.9, indicating a high severity level. Customers using GitLab's hosted AI Gateway are not affected and do not need to take action. GitLab has contacted affected customers with guidance prior to the public advisory. The flaw was reported by a researcher on HackerOne, and the first public proof of concept was released on October 3, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-1868 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Who is affected by CVE-2026-90970?
What should I do if I'm using a self-hosted AI Gateway?
Is there any evidence of exploitation in the wild?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…