Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
Reported exploitedGiteaOur summary
CISA has confirmed active exploitation of CVE-2026-60004, a critical code injection flaw in the Gitea Git platform, listing it in its Known Exploited Vulnerabilities catalog. Attackers leverage the diffpatch endpoint to execute arbitrary shell commands, allowing them to deploy cryptocurrency miners on self-hosted instances where open registration is enabled. A detailed incident report highlights how automated scanners compromised outdated deployments within seconds, granting access to sensitive configuration files and environment variables. Administrators are advised to immediately upgrade to Gitea v1.27.2, disable unauthenticated account creation, and rotate all exposed secrets.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.