Critical Gogs Zero-Day Exploited! 700+ Servers Compromised - What You Need to Know (2026)

Over 700 self-hosted Gogs instances have been compromised in zero-day attacks, with no immediate fix available. Attackers are exploiting a previously unknown flaw in Gogs, a popular self-hosted Git service, which was responsibly disclosed to the maintainers. The vulnerability, tracked as CVE-2025-8110, allows authenticated users to overwrite files outside the repository, leading to remote code execution (RCE). This bug is a bypass of a previously patched issue (CVE-2024-55947) and affects Gogs servers running version 0.13.3 or earlier with open-registration enabled. The fix for the earlier RCE didn't account for symbolic links, enabling attackers to execute malicious code in four steps, which are easily achievable for users with default repository creation permissions. The attacks have been attributed to a potential Asian-based group using the Supershell remote command-and-control framework, and the intruders' activities with access to vulnerable instances remain unclear. To mitigate the risk, Wiz recommends disabling open-registration and limiting internet exposure by placing self-hosted Git services behind a VPN. Users should also monitor for newly created repositories with random 8-character names or unusual API usage. The full list of indicators of compromise is available for reference.

Critical Gogs Zero-Day Exploited! 700+ Servers Compromised - What You Need to Know (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Mr. See Jast

Last Updated:

Views: 6202

Rating: 4.4 / 5 (55 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Mr. See Jast

Birthday: 1999-07-30

Address: 8409 Megan Mountain, New Mathew, MT 44997-8193

Phone: +5023589614038

Job: Chief Executive

Hobby: Leather crafting, Flag Football, Candle making, Flying, Poi, Gunsmithing, Swimming

Introduction: My name is Mr. See Jast, I am a open, jolly, gorgeous, courageous, inexpensive, friendly, homely person who loves writing and wants to share my knowledge and understanding with you.