Gogs argument-injection RCE (CVE id claimed by S3 sub-agent — unverified against authoritative NVD entry; Rapid7 publication states no CVE assigned at disclosure; deferred to next-run verification)
cve · CVE-2026-26194
Coverage timeline
1
first 2026-05-29 → last 2026-05-29
Briefs
1
1 distinct
Sources cited
21
15 hosts
Sections touched
0
—
Co-occurring entities
0
no co-occurrence
Story timeline
- 2026-05-29CTI Daily Brief — 2026-05-29
Source distribution
- rapid7.com5 (24%)
- blog.talosintelligence.com2 (10%)
- securityweek.com2 (10%)
- bleepingcomputer.com1 (5%)
- cisa.gov1 (5%)
- cyberscoop.com1 (5%)
- docs.gitlab.com1 (5%)
- globenewswire.com1 (5%)
- other7 (33%)
External references
All cited sources (21)
- rapid7.comprimaryinlineRapid7 ETRhttps://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass/
- rapid7.comprimaryinlineRapid7 — Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomwarehttps://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/
- rapid7.comprimaryinlineRapid7 Q1 2026 Threat Landscape Reporthttps://www.rapid7.com/blog/post/tr-q1-2026-threat-landscape-report-geopolitics-ransomware/
- rapid7.comprimaryinlineworking Metasploit module against an unpatched Gogs zero-dayhttps://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/
- rapid7.comprimaryinlineRapid7, 2026-05-14https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/
- bleepingcomputer.cominlineBleepingComputer — MuddyWater hackers use Chaos ransomware as a decoyhttps://www.bleepingcomputer.com/news/security/muddywater-hackers-use-chaos-ransomware-as-a-decoy-in-attacks/
- blog.talosintelligence.cominlineCisco Talos, 2026-05-14https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/
- blog.talosintelligence.cominlineTalos UAT-8616 deep dive, 2026-02-25https://blog.talosintelligence.com/uat-8616-sd-wan/
- cisa.govinlineCISA ED-26-03, 2026-05-14https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems
- cyberscoop.cominlineCyberScoop, 2026-05-05https://cyberscoop.com/cpanel-authentication-bypass-vulnerability-cve-2026-41940-exploited/
- docs.gitlab.cominlineGitLab patch-release pagehttps://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-1-released/
- globenewswire.cominlineGlobeNewswire — Rapid7 Q1 2026 releasehttps://www.globenewswire.com/news-release/2026/05/21/3299378/36514/en/Rapid7-Q1-2026-Threat-Landscape-Report-Finds-Vulnerability-Exploitation-Overtakes-Social-Engineering-as-the-Top-Initial-Access-Vector.html
- helpnetsecurity.cominlineHelp Net Security, 2026-05-04https://www.helpnetsecurity.com/2026/05/04/multiple-threat-actors-actively-exploit-cpanel-vulnerability-cve-2026-41940/
- labs.watchtowr.cominlinewatchTowr Labshttps://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
- maine.govinlineMaine AG filinghttps://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/d6729ef2-7bb3-42d3-abdd-99a1dd8f2415.html
- prnewswire.cominlinePR Newswire substitute noticehttps://www.prnewswire.com/news-releases/carnival-corporation-notice-of-data-breach-302783524.html
- sec.cloudapps.cisco.cominlineCisco PSIRT cisco-sa-sdwan-rpa2-v69WY2SW, 2026-05-14https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW
- securityweek.cominlineSecurityWeek, 2026-05-15https://www.securityweek.com/cisco-patches-another-sd-wan-zero-day-the-sixth-exploited-in-2026/
- securityweek.cominlineSecurityWeek — Iranian APT intrusion masquerades as Chaos ransomware attackhttps://www.securityweek.com/iranian-apt-intrusion-masquerades-as-chaos-ransomware-attack/
- thehackernews.cominlineHacker News writeuphttps://thehackernews.com/2026/05/critical-gogs-rce-vulnerability-lets.html
- verizon.cominlineVerizonhttps://www.verizon.com/about/news/breach-industry-wide-dbir-finds
Items in briefs about Gogs argument-injection RCE (CVE id claimed by S3 sub-agent — unverified against authoritative NVD entry; Rapid7 publication states no CVE assigned at disclosure; deferred to next-run verification)
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.