# GitLab patches multiple vulnerabilities across CE/EE

Published: 2026-09-24 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/8c2c30c8-1d70-52b3-b514-759a399d5c1f/gitlab-patches-multiple-vulnerabilities-across-ce-ee

> CERT-FR advises patching GitLab CE/EE for multiple flaws enabling code execution, data disclosure, and XSS.

CERT-FR published an advisory covering multiple vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE). The flaws affect versions 19.3.x prior to 19.3.3, 19.4.x prior to 19.4.1, and all versions prior to 19.2.7. Collectively, the vulnerabilities could allow an attacker to achieve arbitrary code execution, compromise data confidentiality and integrity, bypass security policies, and conduct remote indirect code injection (cross-site scripting).

Eleven CVEs are referenced in the bulletin (CVE-2026-10518, CVE-2026-4523, CVE-2026-84739, CVE-2026-89078, CVE-2026-8937, CVE-2026-92470, CVE-2026-92529, CVE-2026-92530, CVE-2026-92628, CVE-2026-92874, CVE-2026-93577), tied to GitLab's own security release dated 23 September 2026. No detail is given on individual vulnerability mechanics or exploitation status in this advisory.

Defenders running self-hosted GitLab CE/EE should prioritize upgrading to the fixed versions (19.4.1, 19.3.3, or 19.2.7 and later) referenced in GitLab's official patch release notes. No in-the-wild exploitation is mentioned in this advisory; treat as a routine but timely patch action given the range of impacts including RCE.

## Mentioned in this report

- Vulnerabilities: CVE-2026-10518, CVE-2026-4523, CVE-2026-84739, CVE-2026-89078, CVE-2026-8937, CVE-2026-92470, CVE-2026-92529, CVE-2026-92530, CVE-2026-92628, CVE-2026-92874, CVE-2026-93577

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1225

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8c2c30c8-1d70-52b3-b514-759a399d5c1f/gitlab-patches-multiple-vulnerabilities-across-ce-ee.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
