Back to advisories

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Gitea instances are under active attack for CVE-2026-60004, a critical RCE flaw (CVSS 9.8) that allows unauthenticated account creation to trigger arbitrary command execution. Attackers are deploying miner-like payloads. Any organization running Gitea with default open registration is at immediate risk.

CRITICALAdvisoryAug 26, 2026
Action required
Immediately scan your environment for Gitea instances, disable open registration, apply available patches, and hunt for suspicious process execution and outbound connections indicative of cryptominer activity on affected systems.
Affected products
GiteaCISA