Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
CD PROJEKT SA

CD PROJEKT SA Vendor Cyber Rating & Cyber Score

cdprojekt.com

The CD PROJEKT Capital Group has been operating in the video game industry for over 20 years. It specializes in the development of cutting-edge interactive entertainment (CD PROJEKT RED) and worldwide digital distribution of video games (GOG.com). Founded in 2002, CD PROJEKT RED is a Polish game development studio headquartered in Warsaw, with offices in Kraków and Wrocław, and international branches in Los Angeles and Shanghai. The studio's flagship franchise, games from The Witcher series, has sold over 33 million copies worldwide. Its most recent installment — The Witcher 3: Wild Hunt — debuted in 2015 for the PC, PlayStation 4 and Xbox One, and has since received over 800 awards and accolades, including 250 Game of the Year awards.


CPS A.I CyberSecurity Scoring

CPS
Company Information
Website:http://www.cdprojekt.com
Employees number:88
Number of followers:24,691
NAICS:51126
Industry Type:Computer Games
Homepage:cdprojekt.com
CPS Risk Score (AI oriented)
Between 750 and 799
logo
CPSComputer Games
Updated:
02/04/2026
750/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
CPS Global Score (TPRM)
xxxx
logo
CPSComputer Games
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CPS
CPSFair
Current Score
750Baa (FAIR)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
751Before Incident
MAY 2026
750Before Incident
APRIL 2026
750Before Incident
MARCH 2026
750Before Incident
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
752Before Incident
Vulnerability
01 Nov 2025CPS
CD PROJEKT SA: Hackers exploit unpatched Gogs zero-day to breach 700 servers

Gogs Zero-Day Vulnerability Exploited for Remote Code Execution (CVE-2025-8110)

749After Incident
CRITICAL-3
CD-1765461818
Hundreds of Gogs Servers Compromised via Unpatched Zero-Day Vulnerability A critical zero-day vulnerability (CVE-2025-8110) in Gogs, a self-hosted Git service, has allowed attackers to execute remote code on exposed instances, compromising hundreds of servers. The flaw stems from a path traversal weakness in the PutContents API, enabling threat actors to bypass protections for a previously patched RCE bug (CVE-2024-55947) by exploiting symbolic links to overwrite sensitive system files. While Gogs versions patched for CVE-2024-55947 now validate path names, they fail to check symlink destinations. Attackers exploit this by creating repositories with symlinks pointing to critical files—such as Git’s sshCommand configuration—allowing arbitrary command execution when data is written via the API. Wiz Research discovered the vulnerability in July 2024 after investigating a malware infection on a customer’s exposed Gogs server. Their scan identified over 1,400 publicly accessible Gogs instances, with 700+ showing signs of compromise. All affected servers exhibited identical attack patterns, including repositories with random eight-character names created in the same timeframe, suggesting a single automated campaign. The deployed malware, built using Supershell—an open-source C2 framework—established reverse SSH shells, communicating with a command-and-control server at 119.45.176[.]196. Many exposed instances had open registration enabled by default, expanding the attack surface. Gogs maintainers were notified on July 17, acknowledging the flaw on October 30 while developing a patch. A second wave of attacks was observed on November 1, underscoring the urgency of mitigation. The vulnerability remains unpatched as of the latest disclosure.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: System files and Git configurations overwritten; potential data exfiltration via malwareSystems Affected: Over 700 Gogs servers compromised out of 1,400 exposed onlineOperational Impact: Arbitrary command execution on compromised servers; potential disruption of Git servicesBrand Reputation Impact: Potential reputational damage for organizations using vulnerable Gogs instances
DATA BREACH
Type Of Data Compromised: System files, Git configurations, potential exfiltration of sensitive data via malwareSensitivity Of Data: High (system-level access, potential for further exploitation)Data Exfiltration: Possible via Supershell malware (C2 communication detected)File Types Exposed: Git configuration files, symbolic links, system files
OCTOBER 2025
752Before Incident
SEPTEMBER 2025
752Before Incident
AUGUST 2025
752Before Incident
JULY 2025
752Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CPS ?
?
What was CPS's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CPS's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CPS's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CPS's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CPS's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CPS's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CPS's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CPS's A.I Rankiteo Cyber Score in October 2025 ?
?
What was CPS's A.I Rankiteo Cyber Score in September 2025 ?
?
What was CPS's A.I Rankiteo Cyber Score in August 2025 ?
?
What was CPS's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on CPS's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CPS ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CPS's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
CD PROJEKT SA Cyber Scoring History | Rankiteo