CVE Tools

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Help Net SecurityBy Zeljka Zorz

Reported exploitedGitea

Our summary

CISA has confirmed active exploitation of CVE-2026-60004, a critical code injection flaw in the Gitea Git platform, listing it in its Known Exploited Vulnerabilities catalog. Attackers leverage the diffpatch endpoint to execute arbitrary shell commands, allowing them to deploy cryptocurrency miners on self-hosted instances where open registration is enabled. A detailed incident report highlights how automated scanners compromised outdated deployments within seconds, granting access to sensitive configuration files and environment variables. Administrators are advised to immediately upgrade to Gitea v1.27.2, disable unauthenticated account creation, and rotate all exposed secrets.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store