logo

CISA “Must-Patch” Alert: Critical Gogs Exploit CVE-2025-8110 Active in Wild

ID: 11d31ae0-c6ff-5b95-aa14-232fb4aeef20

STIX ID: report--11d31ae0-c6ff-5b95-aa14-232fb4aeef20

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-01-13

Date Updated: 2026-04-23

Author: Ddos

...
...

CISA placed CVE-2025-8110 — a high-severity (CVSS 8.7) symlink-bypass vulnerability in the self-hosted Git service Gogs — on its Must-Patch list after Wiz Research reported active zero-day exploitation on July 10, 2025; the flaw bypasses a previous RCE fix and allows authenticated users to perform path traversal and overwrite files outside repositories to execute arbitrary code, prompting FCEB agencies to remediate by Feb 2, 2026 and administrators to apply updates or restrict internet exposure immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.