:

FORGEJO <=16.0.3 PATCHED FOR CRITICAL RCE

INDUSTRY DESK1 MIN READ
THU, SEP 10, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Forgejo, a self-hosted Git service, released version 16.0.4 to address a critical remote code execution vulnerability affecting all versions up to 16.0.3. Users should upgrade immediately.

The vulnerability allows unauthenticated attackers to execute arbitrary code on affected Forgejo instances. Details are available in the [16.0.4 release notes](https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/16.0.4.md). Forgejo is a community-driven fork of Gitea designed for self-hosting. The flaw represents a severe risk to organizations running vulnerable versions, particularly those exposed to untrusted networks. Administrators must prioritize upgrading to version 16.0.4 or later. The security patch was released without advance notice, suggesting the vulnerability was actively exploited or posed immediate risk. The disclosure gained significant attention on developer communities, with over 100 points and dozens of comments on Hacker News, indicating widespread awareness among the self-hosted software community.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Trezor alerted customers Wednesday that attackers exploited a breach at its third-party email provider to launch phishing campaigns. The cryptocurrency hardware wallet maker urged users to remain vigilant against fraudulent communications.

1H AGOAI Desk

Microsoft's September 2026 security patches are disabling Remote Desktop Services across Windows Server 2019, 2022, and 2025, leaving administrators unable to access systems and requiring hard resets in some cases.

1H AGOIndustry Desk

Surfshark disclosed that hackers accessed internal testing and proxy servers following a configuration error that exposed systems to the internet. The VPN provider is investigating the scope of the breach.

2H AGOSecurity Desk

Google has enabled Android users to securely migrate login credentials between password managers. The feature is currently available in a limited number of apps, with broader support expected soon.

2H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.