CISA Warns of Exploited Gitea Vulnerability
Reported exploitedGiteaOur summary
CISA has identified active exploitation of a remote code execution flaw in the self-hosted Git hosting platform Gitea. The vulnerability, designated as CVE-2026-60004, enables attackers with repository write access to inject malicious Git hooks through the diffpatch API endpoint. This defect was remediated in release version 1.27.1, and the agency has mandated that federal systems apply the patch immediately.
Read at SecurityWeek
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.