Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncD CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel U. S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog AI Agents Attempt SQL Injection While Searching Government Data Investigators trace an AI agent ‘s path from research task to reconnaissance U. S.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed

GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to execute arbitrary commands on the gateway. GitLab disclosed the flaw on October 2 and fixed it with the release of AI Gateway versions 19. 2. 4, 19. 3. 2 and 19. 4. 1. The issue affects the way the AI Gateway handles custom flow prompt templates. According to GitLab, a user with Duo Agent Platform access could use a specially crafted flow configuration to escape the prompt template sandbox and execute commands on the AI Gateway host.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-90970: Critical GitLab AI Gateway Flaw Enables Command Execution

GitLab patched CVE-2026-90970, a critical 9.9-rated AI Gateway flaw that could let authenticated Duo Agent Platform users escape a template sandbox and execute arbitrary commands. The post CVE-2026-90970: Critical GitLab AI Gateway Flaw Enables Command Execution appeared first on CyberUpdates365 • Latest Cybersecurity News & Vulnerabilities .

·Cyber Updates 365
Read →
Vulnerabilities & Patches
Emerging1 src

GitLab Patches Critical AI Gateway Flaw Allowing Arbitrary Command Execution

GitLab has released critical security updates for its AI Gateway to address CVE-2026-90970, a vulnerability that could allow authenticated users to execute arbitrary commands on vulnerable self-hosted deployments. The flaw carries a CVSS score of 9. 9 out of 10 and affects GitLab AI Gateway versions beginning with 18. 1. 6 across several release branches. GitLab issued patched AI Gateway releases 19. 2. 4, 19. 3. 2, and 19. 4. 1, urging all customers operating a GitLab Self-Hosted AI Gateway to upgrade immediately. GitLab Patches Critical AI Gateway Flaw Tracked as CVE-2026-90970, the issue stems from improper neutralization in the custom-flow prompt template mechanism used by GitLab AI Gateway. Under certain conditions, an authenticated user who has access to the Duo Agent Platform could submit a specially crafted flow configuration and escape the prompt-template sandbox.

·CyberPress
Read →
Vulnerabilities & Patches
Emerging1 src

Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks

GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers to execute commands remotely. Tracked as CVE-2026-90970, the flaw carries a CVSS score of 9. 9 and affects self-hosted deployments used to support GitLab Duo AI features. The company released AI Gateway versions 19. 2. 4, 19. 3. 2, and 19. 4. 1 to address the issue. GitLab strongly recommends that customers running affected self-hosted gateways upgrade immediately. It also contacted self-hosted AI Gateway customers before publishing its security advisory to provide early guidance on the required updates. GitLab AI Gateway Vulnerability The vulnerability involves improper handling of custom flow prompt templates.

·Cyber Security News
Read →

You've reached the end of current stories for this search.