CISA: Hackers now exploit max severity GitLab flaw in attacks
BleepingComputer reports that CISA says hackers now exploit a maximum severity GitLab flaw in attacks. The story, published September 14, 2026, describes the vulnerability as maximum severity and states that exploitation is taking place in attacks rather than remaining a theoretical concern. The source does not identify a CVE ID, does not list affected GitLab versions or deployment types, and does not describe the exploitation technique, the attackers, or any victims. The only concrete elements the source provides are the vendor name GitLab, the attribution of the warning to CISA, the maximum severity classification, and the fact of active exploitation. No remediation guidance, patch status, timeline, or affected-user details appear in the excerpt. Because the source text is thin, the digest is limited to those points: a maximum severity GitLab flaw is being exploited, and CISA is cited as the source of that assessment. Any additional specifics, such as which GitLab releases are vulnerable or what actions defenders should take, are not present in the provided text and are therefore not included.
A maximum severity GitLab flaw is being actively exploited, so teams running GitLab should treat the reported attacks as a live risk.