
🚨 GITLAB CRITICAL PATCH: AUTH RCE VIA REGEX PARSER (CVE-2026-89078 / CVE-2026-93577) GitLab released Critical patch versions 19.4.1, 19.3.3, and 19.2.7 on September 23, 2026 for CE/EE. Lead Critical issues (both CVSS 9.9): * CVE-2026-89078 — authenticated remote code execution via a double-free in the regular-expression parser when handling a crafted regex in CI/CD configuration * CVE-2026-93577 — authenticated remote code execution via an integer overflow in the regular-expression compiler under the same class of crafted CI/CD regex input Also in the same release: High XSS in the merge request diff viewer (CVE-2026-84739) plus several Medium/Low authz issues. Impacted: GitLab CE/EE from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 (XSS reach extends further back on some issues). http://GitLab.com is already patched; Dedicated customers need no action. Self-managed installs should upgrade immediately. ⚠️ Analyst Note: This is an official GitLab Critical patch release, not a dark-web leak claim and not a CISA KEV add as of our check. Both Critical RCEs require an authenticated user. No in-the-wild exploitation is claimed in the vendor notes reviewed here. Credit on the Critical regex issues: joaxcar via HackerOne. Primary: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/ #DDW #DarkWeb #GitLab #CVE202689078 #CVE202693577 #RCE #ThreatIntelligence #CyberSecurity






