DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-20896PUBLISHED: 2026-07-03
CRITICALCVE-2026-20896

Gitea Docker Reverse-Proxy Authentication Bypass

VENDOR: Gitea//PRODUCT: Gitea (Docker image)
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

Gitea's official Docker image hard-codes REVERSE_PROXY_TRUSTED_PROXIES=* in app.ini, causing the platform to trust the X-WEBAUTH-USER HTTP header from any source IP when reverse-proxy authentication is enabled. Any unauthenticated attacker who can reach the Gitea port can impersonate any user — including administrators — with a single HTTP header, no password or token required. Sysdig confirmed active exploitation attempts began 13 days after public disclosure, targeting approximately 6,200 internet-accessible Gitea instances; a public PoC and detector tool are available on GitHub from the bug reporter. Successful exploitation exposes all code repositories, secrets, CI/CD credentials, and deploy keys stored in the instance, making it a high-value supply-chain attack vector.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSGitea Docker image versions 1.26.2 and earlier (fixed in 1.26.3 / 1.26.4)
  • https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html
  • https://blog.gitea.com/release-of-1.26.3-and-1.26.4/
  • https://github.com/rz1027/CVE-2026-20896
  • https://www.securityweek.com/critical-gitea-flaw-under-active-exploitation-researchers-warn/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn