SECURITYBLEEPING COMPUTER
Gogs patches critical zero-day enabling remote code execution
Gogs has patched a critical zero-day security flaw that could allow attackers to execute remote code and access repositories, including private ones, on Internet-facing instances.
Related Signal
Adjacent reporting
- New Gogs zero-day flaw lets hackers get remote code execution
- Ivanti warns of new EPMM flaw exploited in zero-day attacks
- GitHub fixes RCE flaw that gave access to millions of private repos
- No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out
- Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
- A critical Palo Alto PAN-OS zero-day is being exploited in the wild