CISA says attackers are exploiting Gitea remote-code-execution flaw CVE-2026-60004

CISA says attackers are actively exploiting a newly patched flaw in Gitea, the self-hosted code hosting platform used by many organizations. The bug, CVE-2026-60004, was fixed in Gitea 1.27.1 and can let an attacker with repository write access send a malicious patch to the diffpatch API endpoint, plant an executable Git hook, and run shell commands as the Gitea service account. CISA added it to the Known Exploited Vulnerabilities catalog and set an August 28 deadline for federal agencies.
Why it matters: Organizations running self-hosted Gitea should treat this as urgent because attackers are already using the flaw in real attacks. Update to a fixed version right away and review who has repository write access on internet-exposed instances.

Sources

Over 8,300 Gitea servers vulnerable to code execution attacks
Sergiu Gatlan 2026.08.28 95% relevant
This source updates the same underlying event by adding exposure scale and urgency: Shadowserver found 8,393 internet-exposed Gitea instances still vulnerable as of August 27, 2026, and notes ongoing attacks likely deploying cryptomining malware. It also reiterates that default self-registration can let unauthenticated attackers gain the repository write access needed to exploit the flaw.
Hackers now exploit critical Gitea flaw in code injection attacks
Sergiu Gatlan 2026.08.26 98% relevant
This article directly updates the same event by confirming CISA added CVE-2026-60004 to the KEV catalog, set an August 28 deadline for federal agencies, and adds detail that observed attacks likely deployed cryptocurrency miners on unpatched Gitea servers.
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
info@thehackernews.com (The Hacker News) 2026.08.26 96% relevant
This article appears to update the same underlying event by adding concrete exploitation details beyond the CISA warning, including that real-world attacks are dropping a miner-like payload after exploiting the Gitea RCE flaw.
CISA Warns of Exploited Gitea Vulnerability
Eduard Kovacs 2026.08.26 100% relevant
This article establishes a distinct new story: active exploitation and KEV listing of CVE-2026-60004 in Gitea, which is separate from previously tracked Gitea flaws involving private container image access, file read, or CVE-2026-20896.
← Back to all stories