GitLab patches 11 flaws, including two 9.9-rated RCEs
GitLab's critical patch release dated September 23, 2026 fixes 11 security flaws, including two remote code execution paths rated 9.9. Fixed versions are 19.4.1, 19.3.3 and 19.2.7 for self-managed instances; GitLab.com and GitLab Dedicated customers are unaffected.
- Patch closes 11 flaws, including two RCEs rated 9.9
- Fixed releases: 19.4.1, 19.3.3 and 19.2.7 by branch
- Affected CVEs: CVE-2026-89078 double free and CVE-2026-93577 integer overflow
- ZoomEye found 1,316,748 exposed GitLab assets on September 24
Read next
Security