Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
The Hacker News published a report on September 14, 2026 describing a campaign in which a threat actor it calls Red Heron exploited a remote code execution vulnerability in Gitea to compromise 13 organizations. According to the article, the victims span six countries. The headline frames the Gitea RCE as the mechanism behind the compromises and attributes the activity to Red Heron. The available source text contains no CVE identifier, no affected Gitea version, no exploitation timeline, and no statement about patching or remediation. It also does not describe the data or systems reached at the 13 organizations, nor does it name the six countries. Because the excerpt is limited to the headline and publication metadata, the digest is restricted to what the source states: a Gitea RCE was exploited, 13 organizations were compromised, and those organizations are located across six countries.
The report ties a Gitea remote code execution flaw to compromises at 13 organizations, making the self-hosted Git service a relevant exposure point for teams running it.