Exploitation timeline
Threadlinqs has recorded 8 GitLab CVEs published between and . The busiest month was 2026-08 (2 new CVEs). 4 of them (50%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 8 of 8 tracked GitLab CVEs.
- CVE-2021-22205critical 10KEVRansomwareEPSS 94.5%
- CVE-2023-7028critical 9.8KEVEPSS 93.3%
- CVE-2021-39935medium 6.8KEVEPSS 41.4%
- CVE-2026-85706critical 10KEVEPSS 1.1%
- CVE-2026-87719critical 9.9EPSS 0.6%
- CVE-2026-6267high 8.5EPSS 0.3%
- CVE-2026-19478critical 9.4
- CVE-2026-19650high 7.1
Products affected
Threadlinqs normalises CPE and CNA product records across all 8 CVEs; 1 distinct GitLab product is affected. The most frequently affected:
- Gitlab 8 CVEs
Threat activity
14 tracked threat campaigns reference GitLab products or exploit GitLab CVEs:
- GitLab AI Gateway critical RCE via prompt template sandbox escape (CVE-2026-90970)CRITICAL
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI EnvironmentsHIGH
- GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706, CVSS 10.0)CRITICAL
- Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public ProjectsCRITICAL
- Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026)MEDIUM
- Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000HIGH
- GitLab Patches 13 Security Flaws (incl. CVE-2026-6267, CVE-2026-12436) Enabling Data Exposure, CI/CD Tampering, and DoSHIGH
- GitLab RCE Chain via Malicious Jupyter Notebooks Exploiting Oj Ruby JSON Parser FlawsCRITICAL
- GitLab RCE via Chained Oj JSON Parser Memory-Safety Flaws (Code Execution as 'git' User)HIGH
- MetaChat Brand Impersonation Phishing Campaign Targets AI API Keys and Credentials via EdgeOne PagesHIGH
- Fodcha — Cross-Architecture DDoS Botnet Spreading via N-Day Exploits (CVE-2021-22205, CVE-2021-35394) and Telnet/SSH Brute-Force, Later Adding Ransom DDoSHIGH
- GitLab CE/EE Security Patch Release (19.0.1 / 18.11.4 / 18.10.7) — CVE-2026-4868 GitLab Duo AI Workflow Runner Identity Confusion (CVSS 8.2) Plus DoS and Broken-Authorization FlawsHIGH
- APT35 (Charming Kitten) GCC Pre-Positioning Cyber Reconnaissance Campaign Enabling Kinetic TargetingCRITICAL
- GitLab CI Lint API SSRF — CVE-2021-39935 Patch Bypass, CISA KEV Feb 2026, Cloud Metadata Theft, Internal Service Enumeration, 4-Year Exploitation Gap on Self-Managed InstancesHIGH
Threat actors targeting GitLab
Named threat actors attributed to campaigns that involve GitLab products or CVEs, with the number of linked campaigns:
How to prioritise GitLab patching
This order follows the data Threadlinqs holds for GitLab, not a generic severity checklist:
- 4 of 8 GitLab CVEs (50%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2021-22205, CVE-2023-7028, CVE-2021-39935.
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2026-87719 (0.6%), CVE-2026-6267 (0.3%).
- 5 CVEs score Critical and 2 High on CVSS v3 (maximum 10, average 8.9); sequence these after KEV and high-EPSS items.
- 2 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.