Hackers are exploiting a maximum-severity vulnerability in GitLab, prompting a warning from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). CISA says threat actors are actively using the flaw in attacks, with the vulnerability rated 10.0 on the CVSS scale.

Both outlets report that CISA’s advisory emphasizes the urgency of the situation and frames the issue as an active exploitation campaign rather than a purely theoretical risk. Infosecurity Magazine highlights the “maximum severity” aspect and the CVSS 10.0 rating, while Bleeping Computer likewise focuses on CISA’s statement that exploitation is underway. Neither source provides additional technical details beyond CISA’s characterization of severity and active use, nor does either describe specific affected GitLab versions, the attack method, or mitigation steps.

Overall, the common point across reporting is that CISA has issued guidance warning of real-world exploitation of a critical GitLab vulnerability, underscored by its top CVSS score.