Related Threat Clusters
-
Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
17 articles · Updated June 9, 2026 -
Anonymous Researcher Publishes Zero-Day Exploits for Major Software Projects
An anonymous researcher known as Bikini has released exploit code for over a dozen zero-day vulnerabilities affecting 15 popular open-source projects, including the Linux kernel and Libssh2. The exploits were disclosed…
4 articles · Updated July 1, 2026 -
Critical Gitea Vulnerability CVE-2026-60004 Actively Exploited
A critical vulnerability in Gitea, tracked as CVE-2026-60004, is being actively exploited by attackers, allowing unauthorized users to execute arbitrary shell commands on vulnerable servers. This flaw affects…
18 articles · Updated August 26, 2026 -
Critical Exploitation of Ruby on Rails Vulnerability CVE-2026-66066 Confirmed
Threat actors are actively exploiting CVE-2026-66066, a critical Ruby on Rails vulnerability known as KindaRails2Shell, which allows unauthenticated attackers to read arbitrary files from servers, potentially leading to…
5 articles · Updated August 31, 2026 -
Gitea Docker Authentication Bypass Vulnerability Under Active Exploitation
CVE-2026-20896 is a critical authentication bypass vulnerability (CVSS 9.8) affecting Gitea Docker images up to version 1.26.2. Discovered on July 3, 2026, the flaw allows unauthenticated remote attackers to impersonate…
16 articles · Updated July 7, 2026 -
Critical Gitea Vulnerability Exposes Server Files to Unauthenticated Attackers
A critical vulnerability in Gitea, identified as CVE-2026-59774, allows unauthenticated attackers to read files accessible to the service account via crafted Org-mode markup. This flaw affects Gitea versions 1.22.1…
3 articles · Updated August 5, 2026 -
Gitea Vulnerability Exposes 30,000 Private Container Images to Attackers
A critical vulnerability, CVE-2026-27771, in Gitea's container registry allowed unauthenticated users to access private container images for nearly four years. Discovered by Noscope in April 2026, the flaw affects over…
8 articles · Updated May 28, 2026 -
Critical Vulnerability CVE-2026-58426 Discovered in Gitea Actions Artifacts V4
CVE-2026-58426, published on July 3, 2026, reveals a critical vulnerability in Gitea Actions Artifacts V4. This flaw allows attackers to exploit HMAC ambiguities in signed URLs, enabling unauthorized cross-repository…
2 articles · Updated July 5, 2026 -
Vulnerabilities Discovered in Forgejo Following Carrot Disclosure
A security researcher identified multiple vulnerabilities in Forgejo, a software platform used by Fedora, including SSRF, cryptographic issues, and authentication flaws. The researcher was able to chain these…
2 articles · Updated April 30, 2026
Recent Intelligence Reports
- Critical Ruby on Rails Vulnerability in Attackers' Crosshairs — Securityweek · August 31, 2026
- Hackers target Gitea servers with critical code injection flaw — Computing · August 27, 2026
- CISA Warns of Exploited Gitea Vulnerability — Oodaloop · August 26, 2026
- CVE-2026-60004: Critical Gitea RCE Exploited to Deploy Miner-Like Payloads — Socprime · August 26, 2026
- Hackers now exploit critical Gitea flaw in code injection attacks — Bleepingcomputer · August 26, 2026
- Hackers now exploit critical Gitea flaw in code injection attacks — Bleepingcomputer · August 26, 2026
- Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) — Feeds2.Feedburner · August 26, 2026
- Active Exploitation Alert: Critical Gitea CVE-2026 — Rescana · August 6, 2026