CISA says attackers are actively exploiting a newly patched flaw in Gitea, the self-hosted code hosting platform used by many organizations. The bug, CVE-2026-60004, was fixed in Gitea 1.27.1 and can let an attacker with repository write access send a malicious patch to the diffpatch API endpoint, plant an executable Git hook, and run shell commands as the Gitea service account. CISA added it to the Known Exploited Vulnerabilities catalog and set an August 28 deadline for federal agencies.
Sergiu Gatlan
2026.08.28
95% relevant
This source updates the same underlying event by adding exposure scale and urgency: Shadowserver found 8,393 internet-exposed Gitea instances still vulnerable as of August 27, 2026, and notes ongoing attacks likely deploying cryptomining malware. It also reiterates that default self-registration can let unauthenticated attackers gain the repository write access needed to exploit the flaw.
Sergiu Gatlan
2026.08.26
98% relevant
This article directly updates the same event by confirming CISA added CVE-2026-60004 to the KEV catalog, set an August 28 deadline for federal agencies, and adds detail that observed attacks likely deployed cryptocurrency miners on unpatched Gitea servers.
info@thehackernews.com (The Hacker News)
2026.08.26
96% relevant
This article appears to update the same underlying event by adding concrete exploitation details beyond the CISA warning, including that real-world attacks are dropping a miner-like payload after exploiting the Gitea RCE flaw.
Eduard Kovacs
2026.08.26
100% relevant
This article establishes a distinct new story: active exploitation and KEV listing of CVE-2026-60004 in Gitea, which is separate from previously tracked Gitea flaws involving private container image access, file read, or CVE-2026-20896.