Overview
GitLab has released security updates addressing multiple vulnerabilities found in its Community Edition (CE) and Enterprise Edition (EE). These vulnerabilities could allow an authenticated attacker to inject and execute malicious scripts within another user’s browser session or through crafted content. Successful exploitation could lead to account compromise, session hijacking, and exposure of sensitive information.
- CVE-2026-6896: Cross-Site Scripting (XSS) Vulnerability (CVSSv3 8.7). Affected Versions: GitLab EE 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2
- CVE-2026-13320: HTML Injection Vulnerability (CVSSv3 7.3). Affected Versions: GitLab CE/EE 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2
Roundcube has released a security update addressing multiple high impact cross-site scripting (XSS) vulnerabilities. These vulnerabilities could allow an attacker to execute malicious scripts within a user’s authenticated webmail session, either automatically when a crafted email is viewed or when a user interacts with a malicious attachment warning. Successful exploitation could lead to session hijacking, credential theft, mailbox compromise, and the exposure of sensitive information.
- CVE-2026-54433: Zero-Click Stored Cross-Site Scripting (XSS) Vulnerability (CVSSv3 TBD)
- CVE-2026-54432: Stored Cross-Site Scripting (XSS) Vulnerability (CVSSv3 TBD)
Affected Versions: < 1.7.2
BeyondTrust has released a security advisory addressing four vulnerabilities in its Remote Support and Privileged Remote Access systems. These vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorised access to systems and privileged accounts, cause service disruption through denial-of-service attacks, or access resources and data beyond their intended permissions. Successful exploitation could lead to compromise of remote access infrastructure, exposure of sensitive information, elevated access within affected environments, and disruption or critical services.
- CVE-2026-40138: Improper Authentication Vulnerability (CVSSv4 9.2)
- CVE-2026-40139: Improper Authentication Vulnerability (CVSSv4 9.2)
- CVE-2026-40140: Uncontrolled Resource Consumption Vulnerability (CVSSv4 8.7)
- CVE-2026-40141: Improper Neutralisation of Special Elements in Data Query Logic Vulnerability (CVSSv4 8.5)
Affected Versions: <= 25.3.2
Recommended Action
Organisations are encouraged to review the appropriate security advisory pages and apply the updates:
GitLab – GitHub Advisory Database
Roundcube – Roundcube Security updates
BeyondTrust – BeyondTrust Security Advisory
If you have any concerns, or have been affected by a cyber-related issue, report it to us by submitting a Cyber Concerns Online Reporting Form.