August 29, 2026
in PaperCut Ships a Second Emergency Patch After Researchers Bypass the First
August 27, 2026
- Gitea CVE-2026-60004 (CVSS 9.8) is under active exploitation, per CISA. Ordinary repository write access is enough to execute arbitrary shell commands as the Gitea user; the fix landed in 1.27.1 in late July, and reported attacks are dropping a miner-like payload (BleepingComputer, The Hacker News). Self-hosted Git is a high-value pivot into build pipelines — treat this as CI/CD compromise, not a web bug.
· Vulnerabilities & Exploits
in When the Sandbox Isn't a Boundary
August 6, 2026
- Critical Gitea flaw lets unauthenticated attackers read any file the service account can access via crafted Org-mode markup (CVE-2026-59774, CVSS 9.8) in versions 1.22.1–1.27.0; fixed in 1.27.1 (The Hacker News).
· Vulnerabilities & Exploits
in OpenAI's Rogue-Agent Post-Mortem: A Swarm That Rebuilt Its Own Message Board
July 30, 2026
- A new Gitea RCE (CVE-2026-60004, CVSS 9.8) lets any repository writer plant a live Git hook and run shell commands as the Gitea service account. Fixed in 1.27.1. The Hacker News
· Vulnerabilities & Exploits
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
July 11, 2026
- Gitea Docker image is under active exploitation via a critical authentication bypass that lets attackers impersonate any user, including administrators, on self-hosted Git instances. A prime foothold for CI/CD and source-code supply-chain compromise. BleepingComputer
· Vulnerabilities & Exploits
in Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat
July 9, 2026
- cve-2026-20896-gitea-poc — a checker for the Gitea Docker
X-WEBAUTH-USER auth bypass now under active exploitation (6,200+ exposed instances); useful for validating your own exposure. GitHub
· New Tools & Releases
in A 15-Year-Old Linux Kernel Bug Hands Root on Every Distro
July 8, 2026
- A critical Gitea authentication bypass, CVE-2026-20896, is being probed in the wild. Official Gitea Docker images up to 1.26.2 with reverse-proxy auth enabled trusted any source IP as a proxy, letting an attacker who reaches the container's HTTP port spoof
X-WEBAUTH-USER and impersonate a known/guessable user — accessing repos and secrets. Fixed in 1.26.3/1.26.4; a public PoC/checker exists, and Sysdig observed first in-the-wild probing 13 days post-disclosure. SecurityWeek
· Vulnerabilities & Exploits
in Synacktiv Drops a Kerberos Reflection Bypass That Hands Attackers SYSTEM
July 7, 2026
- Gitea Docker CVE-2026-20896 (CVSS 9.8) is being probed in the wild 13 days after disclosure. The flaw stems from Gitea trusting the
X-WEBAUTH-USER header from any source IP, letting an unauthenticated internet client gain elevated access, per Sysdig (The Hacker News).
· Vulnerabilities & Exploits
in A 16-Year-Old KVM Flaw Punches Through the Hypervisor Boundary