Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
2026-05-28T19:24:09Z•ed6c96de4e88413b982019ff1e111911696fd30f9c56f4e558b18ee3e0fafaaf
CERT-InCrates.ioFortiClientFortinet EMSGhost CMSGiteaGlassWormGogsKnowledgeDeliverLazarusMFA bypassMuddyWaterPyPISharePointTrapDooractive exploitationcredential theftcryptojackingmacOS malwaremalicious packagenpmremote code executionsupply chainvulnerabilityzero-day disclosure
What happened
Recent reporting from The Hacker News highlights a surge of high-severity vulnerabilities and active exploitation across open-source dev platforms, enterprise products, and supply chains. Key items include a critical Gogs RCE (Rapid7 score 9.4; no CVE yet) that allows authenticated users to achieve arbitrary code execution, active exploitation of a critical FortiClient EMS flaw to deliver credential-stealing malware, and multiple disclosed/weaponized CVEs (Ghost CVE-2026-26980, Gitea CVE-2026-27771, Microsoft SharePoint CVE-2026-45659, KnowledgeDeliver CVE-2026-5426). Also noted are large‑ecos
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- ed6c96de4e88413b982019ff1e111911696fd30f9c56f4e558b18ee3e0fafaaf
- Enrichment time
- 2026-05-28T19:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.