CPS A.I CyberSecurity Scoring
CPS
Company Information
Website:http://www.cdprojekt.com
Employees number:88
Number of followers:24,691
NAICS:51126
Industry Type:Computer Games
Homepage:cdprojekt.com
CPS Risk Score (AI oriented)
Between 750 and 799
CPSComputer Games
Updated:
02/04/2026
02/04/2026
750/1000
Fair
Baa
CPS Global Score (TPRM)
xxxx
CPSComputer Games
Score locked

CPSFair
Current Score
750Baa (FAIR)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
751
MAY 2026
750
APRIL 2026
750
MARCH 2026
750
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
752
Vulnerability
01 Nov 2025 • CPS
CD PROJEKT SA: Hackers exploit unpatched Gogs zero-day to breach 700 servers
Gogs Zero-Day Vulnerability Exploited for Remote Code Execution (CVE-2025-8110)
749
CRITICAL-3
CD-1765461818
Hundreds of Gogs Servers Compromised via Unpatched Zero-Day Vulnerability
A critical zero-day vulnerability (CVE-2025-8110) in Gogs, a self-hosted Git service, has allowed attackers to execute remote code on exposed instances, compromising hundreds of servers. The flaw stems from a path traversal weakness in the PutContents API, enabling threat actors to bypass protections for a previously patched RCE bug (CVE-2024-55947) by exploiting symbolic links to overwrite sensitive system files.
While Gogs versions patched for CVE-2024-55947 now validate path names, they fail to check symlink destinations. Attackers exploit this by creating repositories with symlinks pointing to critical files—such as Git’s sshCommand configuration—allowing arbitrary command execution when data is written via the API.
Wiz Research discovered the vulnerability in July 2024 after investigating a malware infection on a customer’s exposed Gogs server. Their scan identified over 1,400 publicly accessible Gogs instances, with 700+ showing signs of compromise. All affected servers exhibited identical attack patterns, including repositories with random eight-character names created in the same timeframe, suggesting a single automated campaign.
The deployed malware, built using Supershell—an open-source C2 framework—established reverse SSH shells, communicating with a command-and-control server at 119.45.176[.]196. Many exposed instances had open registration enabled by default, expanding the attack surface.
Gogs maintainers were notified on July 17, acknowledging the flaw on October 30 while developing a patch. A second wave of attacks was observed on November 1, underscoring the urgency of mitigation. The vulnerability remains unpatched as of the latest disclosure.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
752
SEPTEMBER 2025
752
AUGUST 2025
752
JULY 2025
752
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CPS ??
What was CPS's A.I Rankiteo Cyber Score in May 2026 ??
What was CPS's A.I Rankiteo Cyber Score in April 2026 ??
What was CPS's A.I Rankiteo Cyber Score in March 2026 ??
What was CPS's A.I Rankiteo Cyber Score in February 2026 ??
What was CPS's A.I Rankiteo Cyber Score in January 2026 ??
What was CPS's A.I Rankiteo Cyber Score in December 2025 ??
What was CPS's A.I Rankiteo Cyber Score in November 2025 ??
What was CPS's A.I Rankiteo Cyber Score in October 2025 ??
What was CPS's A.I Rankiteo Cyber Score in September 2025 ??
What was CPS's A.I Rankiteo Cyber Score in August 2025 ??
What was CPS's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on CPS's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CPS ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CPS's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?