Attackers are actively exploiting CVE-2026-20896, a critical Gitea Docker authentication bypass that grants full repository access with a single HTTP…