Changes since yesterday
- NEW — GitLab AI Gateway:CVE-2026-90970 can let an authenticated Duo Agent Platform user escape a custom-flow prompt-template sandbox and execute arbitrary commands on a self-hosted AI Gateway.
- NEW — Dell CSM:Dell disclosed multiple critical Container Storage Modules flaws. CVE-2026-63688 and CVE-2026-63692 both score 10.0 and can give unauthenticated network attackers administrative control.
- NEW — Frontline Education:school districts began receiving breach notifications after a vulnerability in third-party software allowed unauthorized access to part of Frontline’s environment.
Priority actions
- Immediate:Upgrade self-hosted GitLab AI Gateway to 19.2.4, 19.3.2, 19.4.1 or later. GitLab-hosted gateways have already been fixed.
- Immediate:Inventory Dell CSM Authorization/Operator deployments and move to the vendor-remediated release; rotate authorization signing secrets where the advisory calls for it.
- Today:School districts receiving Frontline notifications should scope affected employee records, coordinate notification requirements and monitor for identity-fraud risk.
Priority threats
GitLab AI Gateway CVE-2026-90970 escapes the prompt-template sandbox
- Severity
- Critical
- Status
- No confirmed exploitation reported by GitLab
- CVSS
- 9.9
- CVE
- CVE-2026-90970
- Affected
- Self-hosted GitLab AI Gateway 18.1.6 through affected 19.4 branches
An authenticated user with Duo Agent Platform access can provide a crafted flow configuration that escapes the prompt-template sandbox and leads to arbitrary command execution on the AI Gateway. GitLab already fixed hosted gateways; self-hosted installations need an update.
Upgrade to 19.2.4, 19.3.2, 19.4.1 or later as appropriate. Review custom-flow access and gateway logs if untrusted or broad user groups could create flows.
Sources (1)
Dell CSM authorization flaws can expose storage-admin control
- Severity
- Critical
- Status
- Dell has not reported active exploitation
- CVSS
- 10.0 for CVE-2026-63688 and CVE-2026-63692
- CVE
- CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273
- Affected
- Dell Container Storage Modules deployments described in DSA-2026-448
CVE-2026-63688 lacks authentication on the storage gRPC service and can expose backend administrator credentials for registered arrays. CVE-2026-63692 is a second missing-authentication flaw in the authorization proxy/tenant service that can provide administrative privileges. The same advisory includes critical privilege-escalation, hard-coded-secret and Kubernetes Secrets/RBAC issues.
Upgrade Dell CSM per DSA-2026-448 and review the advisory’s credential-rotation guidance. Systems combining Kubernetes with Dell storage should treat CSM Authorization as part of the cluster’s security boundary.
Confirmed incidents
Frontline Education disclosed unauthorized access through third-party software
- Severity
- High
- Status
- Confirmed data-breach notification
- Affected
- Employee records at notified school districts; scope varies by organization
Frontline Education said it identified a vulnerability in third-party software on August 14 that allowed unauthorized access to part of its environment. The company engaged an external cybersecurity firm, remediated the issue and contacted law enforcement. At least one district notification included employee data such as Social Security numbers, email addresses and physical addresses.
Treat the data scope as district-specific until a broader vendor statement establishes otherwise. Organizations receiving notice should validate which employee fields were exposed rather than assuming every Frontline customer had the same impact.
Sources (1)
Daily observations
- GitLab’s issue is an AI-product vulnerability, but the failure mode is conventional command execution after a sandbox escape; response should follow normal privileged-service hardening.
- Dell CSM sits between Kubernetes and enterprise storage. Authentication failures in that layer can cross both cluster and storage administrative boundaries.
0 comments