Threat Brief — 2026-08-26 — Active Exploitation Spreads to GitLab
GitLab's critical GraphQL flaw (CVE-2026-19478) has moved from disclosure to in-the-wild exploitation in just days, joining an already crowded field of actively exploited dev-platform vulnerabilities. Norway's government DDoS disruption is now in its third day with no resolution. Two unpatched Kaltura video-player flaws add to the growing patch queue — file read and RCE, no fix available.
Top items
- GitLab CVE-2026-19478 now exploited in the wild. watchTowr reports attackers began exploiting the critical GraphQL project-deletion vulnerability only days after disclosure. This is a genuine development: the flaw was first reported on 2026-08-17 by The Hacker News, but active exploitation is now confirmed. Unauthenticated remote actors can modify or delete projects. Patch immediately if not already done. (src: xakep)
- Unpatched Kaltura mwEmbed flaws allow unauthenticated file read and RCE. CERT/CC disclosed two vulnerabilities in Kaltura's HTML5 video player library with no patch available. A remote, unauthenticated attacker can read arbitrary server files and execute code. Organizations running Kaltura should isolate or restrict access to affected instances until a fix ships. (src: The Hacker News)
- Norway government DDoS disruption enters third day. The DDoS attack against Norway's digital gateway continues to block access to government services for a third consecutive day — a significant escalation in duration. First reported 2026-08-25 by BleepingComputer; no mitigation timeline has been announced. (src: SecurityLab)
- SharePoint exploit built for hacker contest now threatens 8,500 servers. New detail on the SharePoint authentication-bypass story: the working exploit was originally constructed for a hacking competition and combines two vulnerabilities into a single effective chain. First reported 2026-08-19 via CISA KEV; the contest origin and server-scope figure are new developments. (src: SecurityLab)
Themes
Dev-platform attack surface is under active fire. GitLab (CVE-2026-19478), Gitea (CVE-2026-60004KEV, already in KEV), and SharePoint are all being exploited in the wild simultaneously. Teams running self-hosted dev infrastructure should treat patching these platforms as a P0 this week — attackers are clearly scanning for unpatched instances.
===
