CVE Tools

Более 8300 серверов Gitea уязвимы перед выполнением произвольного кода

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedGitea

Our summary

Researchers have confirmed active exploitation of a critical remote code execution flaw, CVE-2026-60004, affecting over 8,300 internet-facing Gitea servers worldwide. The vulnerability allows attackers with write access to repositories to execute arbitrary shell commands by injecting malicious Git hooks through the diffpatch API endpoint.

Although authentication is required for exploitation, many default configurations permit open registration, making it easy for threat actors to gain entry without stolen credentials. Gitea released a fix in version 1.27.1 on July 27, 2026, but thousands of systems remain unpatched despite CISA adding the bug to its Known Exploited Vulnerabilities catalog.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store