A critical vulnerability in Gitea, tracked as CVE-2026-20896, is being actively exploited. The flaw lets attackers bypass authentication with a single HTTP header to access repositories and secrets.

A critical security vulnerability in the popular open-source Git service Gitea is currently being actively exploited by attackers, according to security researchers. The flaw, identified as CVE-2026-20896, allows unauthorized individuals to bypass authentication mechanisms and gain access to sensitive data, including private repositories and secrets.
The vulnerability reportedly stems from an improper handling of a specific HTTP header. By crafting a malicious request that includes this header, an attacker can circumvent Gitea's normal authentication procedures. This bypass effectively grants them the same level of access as a logged-in user, potentially exposing the entire contents of repositories they should not have access to.
The implications of this exploit are significant. Gitea is widely used by individuals and organizations for hosting their Git repositories, which often contain proprietary code, intellectual property, and sensitive configuration details. The ability for an attacker to access these resources without proper authentication poses a severe risk of data theft, code leakage, and the compromise of other connected systems through exposed secrets.
While the exact nature of the active exploitation is not detailed, the fact that it is occurring in the wild suggests that threat actors are aware of the vulnerability and are actively attempting to leverage it against Gitea instances. This elevates the urgency for users to address the issue.
Details surrounding the specific HTTP header and the precise technical steps required to exploit CVE-2026-20896 have not been publicly disclosed, likely to prevent further widespread exploitation while mitigation efforts are underway. However, the core mechanism involves tricking the application into believing the request originates from an authenticated source.
Gitea is a lightweight, self-hosted Git service written in Go. Its ease of installation and use has made it a popular choice for developers and teams seeking an alternative to larger, more complex Git hosting solutions. The widespread adoption of Gitea means that a significant number of users could be vulnerable to this attack.
Users of Gitea are strongly advised to monitor official Gitea security advisories for information on patches and updates. Applying any available security updates as soon as they are released is the most effective way to protect against known vulnerabilities.
In the absence of immediate patches, organizations should review their Gitea instance's security posture. This could include implementing stricter network access controls, monitoring access logs for suspicious activity, and ensuring that any exposed secrets are rotated or revoked if a compromise is suspected. General security best practices, such as keeping all software up-to-date and employing robust authentication methods for all systems, remain crucial.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.