CVE Tools

CISA Warns of Exploited Gitea Vulnerability

SecurityWeekBy Eduard Kovacs

Reported exploitedGitea

Our summary

CISA has identified active exploitation of a remote code execution flaw in the self-hosted Git hosting platform Gitea. The vulnerability, designated as CVE-2026-60004, enables attackers with repository write access to inject malicious Git hooks through the diffpatch API endpoint. This defect was remediated in release version 1.27.1, and the agency has mandated that federal systems apply the patch immediately.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store