Over 8,300 Gitea Servers Remain Unpatched Amid Active Exploitation
Shadowserver warns of critical remote code execution flaw affecting Internet-exposed instances

Key Takeaways
- Over 8,300 Internet-exposed Gitea servers are unpatched and actively targeted.
- The vulnerability affects Gitea versions 1.22.0 and earlier.
- Active exploitation of the flaw is being observed in the wild.
- A security patch has been released by Gitea; immediate application is required.
Quick answers
- What happened?
- A critical remote code execution vulnerability in Gitea version 1.22.0 and earlier is being actively exploited in the wild. According to the Shadowserver Foundation, more than 8,300 Internet-exposed Gitea instances remain unpatched despite the availability of a security update. Successful exploitation could allow attackers to execute arbitrary code on affected servers.
- Which products are affected?
- Gitea
- What should defenders do?
- Apply the latest Gitea security update immediately. Administrators should ensure all Gitea instances are updated to the patched version to prevent exploitation.
The Shadowserver Foundation has identified over 8,300 Internet-exposed Gitea servers that remain unpatched against a critical security flaw. The vulnerability, affecting Gitea versions 1.22.0 and earlier, is being exploited for remote code execution (RCE) in ongoing attacks. Cybersecurity watchdog Shadowserver reported that despite the availability of a patch from Gitea, a significant number of server operators have yet to apply the update, leaving their instances exposed. The exact CVE identifier was not disclosed in the initial reporting, but the impact is described as critical, with potential for arbitrary code execution, data theft, and full server compromise. Gitea administrators are urged to apply the latest security updates immediately to mitigate the risk.
Security Details
The vulnerability affects Gitea versions 1.22.0 and earlier and is being actively exploited for remote code execution. Successful exploitation could allow attackers to execute arbitrary code on affected servers. The specific CVE identifier was not provided in the source material.
Affected products
Gitea
Mitigation
Apply the latest Gitea security update immediately. Administrators should ensure all Gitea instances are updated to the patched version to prevent exploitation.
Sources
BleepingComputer
Over 8,300 Gitea servers vulnerable to code execution attacks
Aug 28, 2026 · 12:58
Original link
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.



