Active GitLab Attacks Put Source Code and Secrets at Risk
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Sunday, September 13th, 2026.
Self-managed GitLab servers are under active attack through a weakness that can expose sensitive files without an account or any user interaction. CISA added the issue to its priority catalog on September 11th. The affected releases include versions 18.7 through 19.1.7, 19.2 through 19.2.5 and 19.3 through 19.3.1. The fixed releases are 19.1.8, 19.2.6 and 19.3.2 or later.
Successful exploitation could reveal source code, access tokens, deployment scripts, configuration data and other secrets stored on the server. Internet-facing, self-managed installations have the clearest exposure. GitLab.com was already running the patched version, and GitLab Dedicated customers did not need to act. For leaders, this should be treated as a development and software supply-chain risk rather than a routine server problem. For defenders, patching alone may not be enough because exploitation is already occurring. Upgrade exposed servers immediately, review repository commits A P I and reverse-proxy logs for unusual requests, and rotate credentials that may have been disclosed.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.