Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details about the attacks, but according to an incident report published by a professed full-stack developer on the Russian collaborative blog Habr, someone has exploited the vulnerability to compromise their organization’s self-hosted Gitea instance and run … More → The post Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) appeared first on Help Net Security .

·Help Net Security
Read →
Vulnerabilities & Patches
Emerging1 src

U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog . Gitea is an open-source platform for hosting and managing Git repositories. Think of it as a self-hosted alternative to GitHub or GitLab. CVE-2026-60004 is a critical remote code execution flaw that allows an attacker with write access to a repository to execute arbitrary shell commands as the Gitea service user. The flaw affects Gitea versions from 1. 17 and was fixed in 1. 27. 1. The vulnerable diffpatch API can be abused to plant and execute a malicious Git hook.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Warns of Exploited Gitea Vulnerability

CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1. 27. 1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek .

·SecurityWeek
Read →
Vulnerabilities & Patches
Emerging1 src

Gitea security advisory (AV26-845)

Serial Number: AV26-845 Date: August 25, 2026 As of August 14, 2026, Gitea is affected by vulnerabilities in the following product: • Gitea • Prior to 1.27.1 On August 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-60004 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. • Remote Code Execution via diffpatch Git Hook Installation • Gitea 1.27.1 is released • Gitea 1.27.2 is released • CISA KEV: CVE-2026-60004 Gitea security advisory (AV26-845) - Canadian Centre for Cyber Security

·Malware.news
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-60004 Gitea Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-60004 - Gitea Code Injection Vulnerability

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

·CISA KEV
Read →

You've reached the end of current stories for this search.