Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

2026-05-28T19:24:09Zed6c96de4e88413b982019ff1e111911696fd30f9c56f4e558b18ee3e0fafaaf
CERT-InCrates.ioFortiClientFortinet EMSGhost CMSGiteaGlassWormGogsKnowledgeDeliverLazarusMFA bypassMuddyWaterPyPISharePointTrapDooractive exploitationcredential theftcryptojackingmacOS malwaremalicious packagenpmremote code executionsupply chainvulnerabilityzero-day disclosure

What happened

Recent reporting from The Hacker News highlights a surge of high-severity vulnerabilities and active exploitation across open-source dev platforms, enterprise products, and supply chains. Key items include a critical Gogs RCE (Rapid7 score 9.4; no CVE yet) that allows authenticated users to achieve arbitrary code execution, active exploitation of a critical FortiClient EMS flaw to deliver credential-stealing malware, and multiple disclosed/weaponized CVEs (Ghost CVE-2026-26980, Gitea CVE-2026-27771, Microsoft SharePoint CVE-2026-45659, KnowledgeDeliver CVE-2026-5426). Also noted are large‑ecos

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ed6c96de4e88413b982019ff1e111911696fd30f9c56f4e558b18ee3e0fafaaf
Enrichment time
2026-05-28T19:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code · Baitaphish