[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:critical-gitea-rce-actively-exploited-as-reported-attack-drops-miner-like-payloa-mtaeo6pp":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":16,"article_ids":17,"ioc_summary":19,"source_urls":20,"status":22,"expires_at":23,"created_at":24,"updated_at":25,"articles":26},"0c6c19f1-547c-4534-a1fb-7109713ea2eb","Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload","critical-gitea-rce-actively-exploited-as-reported-attack-drops-miner-like-payloa-mtaeo6pp","Gitea instances are under active attack for CVE-2026-60004, a critical RCE flaw (CVSS 9.8) that allows unauthenticated account creation to trigger arbitrary command execution. Attackers are deploying miner-like payloads. Any organization running Gitea with default open registration is at immediate risk.","critical","advisory",[12],"CVE-2026-60004",[14,15],"Gitea","CISA","Immediately scan your environment for Gitea instances, disable open registration, apply available patches, and hunt for suspicious process execution and outbound connections indicative of cryptominer activity on affected systems.",[18],"982ca648-ebf5-4ee9-906d-54a3cdf88a3d",null,[21],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fcritical-gitea-rce-actively-exploited.html","active","2026-08-28T18:06:36.083+00:00","2026-08-26T18:06:42.751951+00:00","2026-08-26T18:08:41.195176+00:00",[27],{"id":18,"title":6,"url":21}]