Critical Gitea Vulnerability (CVE-2026-59774) Under Active Exploitation, Allowing Unauthenticated File Read and RCE
A critical vulnerability, CVE-2026-59774, in the self-hosted Git service Gitea is being actively exploited. The flaw allows unauthenticated attackers to read arbitrary files from the server by submitting specially crafted Org-mode markup to a public repository. In certain configurations, this can escalate to remote code execution (RCE) as the Gitea operating system user. Organizations are advised to upgrade to Gitea version 1.27.1 or later immediately.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai