CVE-2026-26194 is a vulnerability tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
CVE-2026-26194 is a vulnerability tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed March 6, 2026; most recent activity May 28, 2026.
A critical argument injection vulnerability (CWE-88) has been discovered in Gogs, a widely used self-hosted Git service, allowing authenticated users to execute arbitrary code on the server. The flaw, identified by…
Gogs, an open source self-hosted Git service, has two critical vulnerabilities prior to version 0.14.2. CVE-2026-26276 allows attackers to execute a DOM-Based XSS via malicious HTML/JavaScript in Milestone names, while…
CVE-2026-26194 is a vulnerability tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
The most recent intelligence report mentioning CVE-2026-26194 on ThreatCluster is dated May 28, 2026. Activity was first observed March 6, 2026, giving a tracked span from then to May 28, 2026.
Across ThreatCluster reporting, CVE-2026-26194 most frequently co-occurs with Zero-day Exploit, Gogs, CVE-2024-39930, CVE-2024-39932, CVE-2024-39933, among 12 tracked related entities.
The most significant recent cluster is “Critical Zero-Day Vulnerability in Gogs Allows Remote Code Execution” (10 articles · Updated May 28, 2026). CVE-2026-26194 appears across 2 threat clusters in total, listed above with sources.
CVE-2026-26194 appears in 2 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.