logo

Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw

ID: ead0e8a9-602b-5f4e-9535-1e38bc179bf9

STIX ID: report--ead0e8a9-602b-5f4e-9535-1e38bc179bf9

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-08-22

Date Updated: 2026-08-23

...
...

GitLab's critical CVE-2026-19478 (CVSS 9.4) is being actively exploited to achieve unauthorized code execution shortly after disclosure; concurrently Microsoft Entra ID has an urgent RCE (CVSS 10.0) that requires immediate patch verification. The report also warns of supply-chain attacks against Rust and npm packages and newly observed evasion techniques abusing Microsoft Defender components, emphasizing rapid weaponization within software development lifecycles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.