CVE-2026-60004, a critical code-injection vulnerability in Gitea (self-hosted Git service), was exploited in the wild for remote code execution and cryptocurrency mining. On 26 August 2026, CISA added the flaw to its Known Exploited Vulnerabilities catalog and mandated patches for federal agencies.
7 reportsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
🔴 EXPLOITED Gitea, the self-hosted Git service, has a critical bug (CVE-2026-60004): any user can run code on the server. Open signups let a stranger register and exploit it. Now on CISA's exploited list. Fix: patch to 1.27.1. https:// suriq.io/blog/gitea-cve-2026-6 0004-kev-diffpatch-rce # CVE # CISAKEV # infosec # cybersecurity
CISA warned that attackers are exploiting CVE-2026-60004, a critical code-injection vulnerability in Gitea, and added the flaw to its Known Exploited Vulnerabilities catalog [cybersecuritynews.com#1][thehackernews.com#1][securityweek.com#1]. Gitea is an open-source, self-hosted Git platform used for repository hosting, code review, collaboration and CI/CD. Gitea developers fixed the flaw in versio
CISA has added CVE-2026-60004 to the KEV catalog. The vulnerability in Gitea, a self-hosted Git service, has been exploited in the wild to achieve remote code execution and install cryptocurrency miners on compromised instances. FCEB agencies face a remediation deadline of August 28, 2026. # KnownExploitedVulnerabilities # RemoteCodeExecution # Gitea # CISA https:// cyberworldops.eu/en/cisa-adds-
CISA has listed CVE-2026-60004 in the KEV Catalog. Critical RCE in Gitea actively exploited via malicious patches submitted through the diff API endpoint. Attackers achieve code injection on self-hosted instances and deploy cryptominers on compromised servers. Patch by August 28 is mandatory. # CriticalRCE # GiteaVulnerability # Cryptojacking # CISAKEV https:// cyberworldops.eu/en/gitea-unde r-att
🤖 CVE-2026-60004 (critical): code injection in Gitea lets an attacker with repository write access execute shell commands as the Gitea user via the diffpatch API. Open registration makes it reachable without credentials. Exploited in the wild, added to CISA KEV; patch by Aug 28. Fixed in 1.27.1. 🔗 https://www. bleepingcomputer.com/news/secu rity/hackers-now-exploit-critical-gitea-flaw-in-code-in
CISA Reports Actively Exploited Gitea Critical RCE Vulnerability Gitea patched a critical remote code execution vulnerability (CVE-2026-60004) that attackers are actively exploiting to install crypto-miners on self-hosted instances. The flaw allows users with write access to inject malicious Git hooks via the diffpatch API, potentially exposing database credentials and system secrets. **Update sel