CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[NEW] [high] GitLab: Multiple vulnerabilities

highCVE-2025-9486CVE-2026-15216CVE-2026-15217CVE-2026-15423CVE-2026-16494CVE-2026-16627
An attacker can exploit multiple vulnerabilities in GitLab to perform cross-site scripting attacks, bypass security measures, escalate privileges, disclose confidential information, manipulate data, or cause a denial of service condition.

CSIRTS triage

What
Multiple vulnerabilities in GitLab allow attackers to perform cross-site scripting, bypass security measures, escalate privileges, disclose information, manipulate data, or cause denial of service.
Who is affected
GitLab deployments are affected; specific versions not stated.
Urgency
High severity requires prompt patching; currently not exploited but multiple attack vectors present.
Action
Update GitLab to patched version addressing CVE-2025-9486, CVE-2026-15216, CVE-2026-15217, CVE-2026-15423, CVE-2026-16494, CVE-2026-16627, CVE-2026-18244, and CVE-2026-18433.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch GitLab

Get an email when a new GitLab advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-08-13
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2805

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-9486coverage & exploitation statusNVD · CVE.org
CVE-2026-15216coverage & exploitation statusNVD · CVE.org
CVE-2026-15217coverage & exploitation statusNVD · CVE.org
CVE-2026-15423coverage & exploitation statusNVD · CVE.org
CVE-2026-16494coverage & exploitation statusNVD · CVE.org
CVE-2026-16627coverage & exploitation statusNVD · CVE.org
CVE-2026-18244coverage & exploitation statusNVD · CVE.org
CVE-2026-18433coverage & exploitation statusNVD · CVE.org
CVE-2026-19228coverage & exploitation statusNVD · CVE.org
CVE-2026-4879coverage & exploitation statusNVD · CVE.org
CVE-2026-6821coverage & exploitation statusNVD · CVE.org
CVE-2026-7427coverage & exploitation statusNVD · CVE.org
CVE-2026-8667coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for GitLab

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories