CISA orders feds to patch Gogs RCE flaw exploited in zero-day attacks
ID: 7a1016fe-4bc2-57ae-ba5f-7ddcd00f7e99
STIX ID: report--7a1016fe-4bc2-57ae-ba5f-7ddcd00f7e99
Feed Name: Bleeping Computer
CISA has ordered federal agencies to patch a high-severity Gogs remote code execution vulnerability (CVE-2025-8110) that was actively exploited in zero-day campaigns; the flaw permits authenticated attackers to abuse symlinks in repositories via the PutContents API to overwrite files (including Git config sshCommand) and achieve arbitrary command execution. Wiz Research observed attacks, identified over 1,400 Internet-exposed Gogs instances (with ~1,250 still exposed) and more than 700 showing signs of compromise, and Gogs released patches while CISA added the CVE to its Known Exploited Vulnerabilities catalog with a three-week remediation deadline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
