Critical 9.9
CVE-2026-90970
GitLab Patches Critical RCE Vulnerability CVE-2026-90970 in AI Gateway
Vendor / product: GitLab AI Gateway
Event date: 2026-10-02
Public PoC: Yes
First tracked by RiskWire: 2026-10-03
Sources & citations (3)
- GitLab закрыла критическую RCE-уязвимость в AI Gateway версиями 19.2.4, 19.3.2 и 19.4.1 itzine.ru · 2026-10-02
- GitLab warns of critical RCE vulnerability in AI Gateway service bleepingcomputer.com · 2026-10-02
- Critical GitLab AI Gateway Flaw Lets Attackers Execute Arbitrary Commands gbhackers.com · 2026-10-03
References
See CVE-2026-90970 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →