1. Top Action Item

Patch self-managed GitLab immediately. CVE-2026-19478 (CVSS 9.4) is a code-injection flaw that came under active exploitation within days of public disclosure; per watchTowr, an unauthenticated attacker can modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions. Any organization running self-hosted GitLab with public projects is exposed. Update to the patched GitLab release now and audit project integrity.


2. Exploited This Week

GitLab — CVE-2026-19478


3. Critical Patch Roundup

Microsoft Entra ID — CVE-2026-69836

Cisco Crosswork platforms & Secure Workload — nine flaws, five at CVSS 10.0


4. Home / SOHO Impact


5. Enterprise Impact


6. What To Patch First

  1. GitLab self-managed — patched release — CVE-2026-19478 (exploited in the wild; CVSS 9.4)
  2. Microsoft Entra ID — CVE-2026-69836 (critical; CVSS 10.0 RCE)
  3. Cisco Crosswork / Secure Workload — see source (five CVEs at CVSS 10.0)
  4. Rust crates arrayref / internment / append-only-vec — fixed versions (supply chain; 245M+ downloads)
  5. N-able Passportal — vendor patch (password-vault master key exposure)
  6. Microsoft Office / Windows — current updates — CVE-2026-68801 / CVE-2026-55134 (Excel/Word RCE advisories; see source)

Sources