
Gitea’s RCE Is Now Exploited—Open Registration Widens the Door
CISA added an actively exploited Gitea RCE to its catalog on August 25, 2026. Systems before 1.27.1 need patching, while open registration can give outsiders the required repository access.













