Red Heron Exploits Gitea RCE to Compromise Organizations Globally
Chinese threat actor Red Heron is actively exploiting a critical RCE vulnerability in Gitea, targeting at least 13 organizations across six countries.
A sophisticated Chinese threat actor, identified as Red Heron, is actively exploiting a critical remote code execution (RCE) vulnerability in the widely-used Gitea software. This campaign has already led to the compromise of at least 13 organizations spread across six different countries, underscoring the rapid weaponization of newly disclosed vulnerabilities against popular development platforms.
Acronis Threat Research Unit (TRU) observed Red Heron scanning a substantial number of Gitea instances, specifically identifying 1,386 instances across seven countries. The threat actor also maintained a separate dataset of 477 Gitea instances located in Taiwan, suggesting a focused interest in the region or a broad reconnaissance effort.
The vulnerability in question, identified as CVE-2026-32391, allows unauthenticated attackers to execute arbitrary code on vulnerable Gitea servers. This is achieved by exploiting a flaw in the Gitea API's handling of user-provided data, which can be manipulated to inject malicious commands that are then executed by the server's operating system.
Following the initial compromise, Red Heron appears to be leveraging the access to deploy additional malicious tools and establish persistence. While specific post-exploitation activities are still under investigation, the group's history suggests potential objectives such as intellectual property theft, espionage, or using compromised infrastructure for further attacks.
The rapid exploitation of this Gitea vulnerability highlights a persistent trend in the cybersecurity landscape: threat actors are quick to adapt and exploit zero-day or recently disclosed flaws in software that is integral to software development pipelines and code hosting. Gitea, being a popular self-hosted Git service, presents an attractive target due to its widespread adoption.
Organizations running Gitea instances are strongly advised to apply the latest security patches immediately. The vulnerability has been addressed by the Gitea developers, and proactive patching is the most effective defense against this ongoing campaign. Security teams should also review their network logs for any signs of suspicious activity related to Gitea servers, including unusual outbound connections or unexpected process execution.
This incident serves as a stark reminder of the importance of maintaining up-to-date software and implementing robust security monitoring. The interconnected nature of development tools means that a single vulnerability can have far-reaching consequences, impacting not only the direct victim but potentially their partners and customers as well.
Red Heron's campaign against Gitea instances demonstrates a high level of operational capability and a keen awareness of emerging vulnerabilities. The group's multi-national targeting suggests a broad strategic objective, making it crucial for organizations worldwide to assess their exposure and bolster their defenses against such sophisticated threats.