CISA Warns of Exploited Gitea Vulnerability
CISA warns of exploited Gitea RCE vulnerability CVE-2026-60004, patched in version 1.27.1.
Summary
CISA has issued a warning about a critical remote code execution vulnerability in Gitea, tracked as CVE-2026-60004. This flaw, which allows attackers to plant executable Git hooks and run shell commands, was patched by Gitea developers in version 1.27.1. CISA has added it to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch it by August 28. The exploitation is occurring in the wild, though the actors and their motives remain unclear.
Full text
CISA is warning organizations that a recently patched Gitea vulnerability allowing remote code execution is being exploited in the wild. Gitea is a widely used open source, self-hosted software development platform that provides Git hosting, code review, team collaboration, and CI/CD capabilities. Tracked as CVE-2026-60004, the exploited vulnerability was patched by Gitea developers in late July with the release of version 1.27.1. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog and instructed federal agencies to patch it by August 28. “Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account,” the cybersecurity agency explained. There do not appear to be any previous reports describing exploitation of CVE-2026-60004. It’s currently unclear who is behind the attacks and what their goal is.Advertisement. Scroll to continue reading. This is not the only Gitea vulnerability exploited in the wild in recent months. In early July, organizations were warned about the exploitation of a different flaw, CVE-2026-20896. It’s worth noting that CVE-2026-20896 has yet to be added to CISA’s KEV catalog. Related: Gitea Vulnerability Exposed 30,000 Deployments to Attacks Related: WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Related: CISA Warns of Exploited Oracle WebLogic Vulnerability Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs CISA Warns of Exploited Oracle WebLogic VulnerabilityReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited91 Vulnerabilities Patched in Spring Application FrameworkVenezuelan Gets Record Federal Prison Term for ATM JackpottingPersonal Information Exposed in Apollo Global Data BreachAnthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source FundBanking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the SpotlightContractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind Latest News Linux Foundation to Govern TRACE, an Open Standard for AI Runtime AttestationAlice Raises $140M to Expand AI Model Defenses and Enterprise GuardrailsWordPress Websites Targeted via MiniOrange Plugin VulnerabilitiesWhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security UpdateHands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity ConferenceFirst Malware Built Specifically for Car Head Units Fuels BotnetSilent Patches Don’t Stop Attackers – They Blind DefendersTaiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveDevi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.Forcepoint has named Proofpoint veteran Vincent Merlin as its new Chief Marketing Officer.Vensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer.More People On The MoveExpert Insights Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-60004
- cve — CVE-2026-20896