Vulnerabilities Critical Gitea Flaw Under Active Exploitation, Researchers Warn Attackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets. Ionut ArghireJuly 7, 2026