Federal agencies told to fix or ditch Gogs as exploited zero-day lands on CISA hit list
ID: afb463df-7324-5a28-ba30-da2dab6ed560
STIX ID: report--afb463df-7324-5a28-ba30-da2dab6ed560
Feed Name: The Register (Security)
CISA has ordered federal agencies to stop using or lock down Gogs after a high-severity path traversal vulnerability (CVE-2025-8110) — which allows authenticated users to overwrite arbitrary files and achieve remote code execution via symlink bypass — was added to the Known Exploited Vulnerabilities catalog; researchers report active exploitation with more than 700 confirmed compromised instances and roughly 1,400 internet-reachable servers, and Gogs has not yet released a fix, leaving users to apply mitigations such as disabling registration or shielding instances behind VPNs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
