GitLab attacks put development secrets and supply chains at risk

GitLab attacks put development secrets and supply chains at risk. Development secrets and downstream systems are exposed as attackers exploit a maximum-severity issue in self-managed GitLab.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 15th, 2026.

Development secrets and downstream systems are exposed as attackers exploit a maximum-severity issue in self-managed GitLab. Under certain conditions, an unauthenticated request can read arbitrary files from affected Community and Enterprise Edition servers. Observed activity progressed from initial probing to the theft of configuration files and S S H settings that may contain credentials and CI/CD secrets. CISA added the issue to its Known Exploited Vulnerabilities catalog, and GitLab released fixed versions 19.1.8, 19.2.6, and 19.3.2. Although the immediate access is read-only, stolen secrets can unlock build systems, hosts, cloud services, or other parts of the development environment. Exploitation requires at least one public project, but some organizations may not realize that they have one. Leaders should authorize emergency remediation and assume exposed secrets may need to be replaced. Defenders should patch, review repository commits A P I logs, and remove public access if an immediate update isn’t possible. Update every affected self-managed GitLab instance, and rotate secrets if the logs show probing or exploitation.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

GitLab attacks put development secrets and supply chains at risk
Broadcast by