A maximum-severity flaw in GitLab — requiring no credentials and a single network request — has moved from patch disclosure to active exploitation in under 24 hours, prompting a federal warning from CISA. The vulnerability lays bare the files of any unpatched instance, and the speed of its weaponization reflects a broader truth about the modern threat landscape: the window between disclosure and danger has collapsed to nearly nothing. Organizations that treat patching as a scheduled convenience rather than an urgent imperative now find themselves in the crosshairs of a vulnerability that deman