CVE Tools

Over 8,300 Gitea servers vulnerable to code execution attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedGitea

Our summary

Shadowserver reports that over 8,300 internet-facing Gitea instances remain vulnerable to active remote code execution attacks exploiting CVE-2026-60004. This code injection flaw allows attackers with repository write access—or anyone able to exploit default open registration—to execute arbitrary shell commands via the diffpatch API endpoint. Although Gitea released version 1.27.1 on July 27 to remediate the issue, CISA has since added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated immediate patching for federal agencies.

Recent activity suggests threat actors are leveraging this weakness to deploy cryptocurrency mining malware on compromised systems.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store