Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution

Posted on January 13, 2026January 13, 2026 By CWS

Jan 13, 2026Ravie LakshmananVulnerability / Community Safety
The U.S. Cybersecurity and Infrastructure Safety Company (CISA) has warned of energetic exploitation of a high-severity safety flaw impacting Gogs by including it to its Identified Exploited Vulnerabilities (KEV) catalog.
The vulnerability, tracked as CVE-2025-8110 (CVSS rating: 8.7), pertains to a case of path traversal within the repository file editor that would lead to code execution.
“Gogs Path Traversal Vulnerability: Gogs accommodates a path traversal vulnerability affecting improper Symbolic hyperlink dealing with within the PutContents API that would permit for code execution,” CISA stated in an advisory.
Particulars of the shortcoming got here to gentle final month when Wiz stated it found it being exploited in zero-day assaults. The vulnerability basically bypasses protections put in place for CVE-2024-55947 to attain code execution by making a git repository, committing a symbolic hyperlink pointing to a delicate goal, and utilizing the PutContents API to write down information to the symlink.

This, in flip, causes the underlying working system to navigate to the precise file the symlink factors to and overwrites the goal file outdoors the repository. An attacker might leverage this habits to overwrite Git configuration information, particularly the sshCommand setting, giving them code execution privileges.
Wiz stated it recognized 700 compromised Gogs cases. In accordance with information from the assault floor administration platform Censys, there are about 1,600 internet-exposed Gogs servers, out of which nearly all of them are situated in China (991), the U.S. (146), Germany (98), Hong Kong (56), and Russia (49).
There are at the moment no patches that tackle CVE-2025-8110, though pull requests on GitHub present that the required code modifications have been made. “As soon as the picture is constructed on important, each gogs/gogs:newest and gogs/gogs:next-latest could have this CVE patched,” one of many challenge maintainers stated final week.
Within the absence of a repair, Gogs customers are suggested to disable the default open-registration setting and restrict server entry utilizing a VPN or an allow-list. Federal Civilian Government Department (FCEB) companies are required to use the required mitigations by February 2, 2026.

The Hacker News Tags:Active, CISA, Code, Enabling, Execution, Exploitation, Gogs, Vulnerability, Warns

Post navigation

Previous Post: Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets
Next Post: Hackers Leverage Browser-in-the-browser Tactic to Trick Facebook Users and Steal Logins

Related Posts

Operation Endgame Dismantles Rhadamanthys, Venom RAT, and Elysium Botnet in Global Crackdown The Hacker News
WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories The Hacker News
Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks The Hacker News
New EDDIESTEALER Malware Bypasses Chrome’s App-Bound Encryption to Steal Browser Data The Hacker News
Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control The Hacker News
Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Global Organizations The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SAP Security Patch Day January 2026
  • New Malware Campaign Delivers Remcos RAT Through Multi-Stage Windows Attack
  • New Angular Vulnerability Enables an Attacker to Execute Malicious Payload
  • Cyber Fraud Overtakes Ransomware as Top CEO Concern: WEF 
  • Hackers Leverage Browser-in-the-browser Tactic to Trick Facebook Users and Steal Logins

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SAP Security Patch Day January 2026
  • New Malware Campaign Delivers Remcos RAT Through Multi-Stage Windows Attack
  • New Angular Vulnerability Enables an Attacker to Execute Malicious Payload
  • Cyber Fraud Overtakes Ransomware as Top CEO Concern: WEF 
  • Hackers Leverage Browser-in-the-browser Tactic to Trick Facebook Users and Steal Logins

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark