Hackers started exploiting CVE-2026-19478, a critical, unauthenticated GitLab vulnerability, shortly after public disclosure.