News

CISA added Gitea's CVE-2026-60004 to KEV with an August 28 federal deadline, but its alert names no actor, no miner and no campaign

CISA added one self-hosted Gitea flaw, CVE-2026-60004 (CWE-94 code injection, CVSS 9.8), to its Known Exploited Vulnerabilities catalog on August 25, with a federal remediation deadline of August 28 under BOD 26-04. It was fixed in Gitea 1.27.1 back on July 28 (latest is 1.27.2), it needs repository write access rather than being unauthenticated by design, and CISA lists no threat actor and ransomware use as Unknown. The cryptominer-in-Docker story traces to a single Habr incident report, not to CISA.

CISA added Gitea's CVE-2026-60004 to KEV with an August 28 federal deadline, but its alert names no actor, no miner and no campaign

On August 25, CISA added a single Gitea vulnerability, CVE-2026-60004, to its Known Exploited Vulnerabilities catalog and set a federal remediation deadline of August 28 under Binding Operational Directive 26-04. Read what CISA asserts and what it does not. The CISA alert and the KEV catalog say the flaw is being exploited in the wild and put agencies on a three-day clock, but the listing names no threat actor, no malware and no victim count, and marks ransomware use as Unknown. This is a self-hosted Gitea code-injection flaw, not a GitHub.com cloud zero-day, and the cryptominer story circulating with it is a single incident report's, not CISA's.

The instrument: a code-injection flaw in self-hosted Gitea, not a GitHub.com bug

Name the instrument precisely. Per the Gitea advisory GHSA-rcr6-4jqh-j84m, published July 28, CVE-2026-60004 is a CWE-94 code injection rated CVSS 9.8. SecurityWeek quotes CISA's own characterization: "Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account." That is the instrument, and it is where the how-it-works stops here.

Two corrections belong on the label. First, this affects self-hosted Gitea >=1.17 and <1.27.1, the software teams install on their own servers, not GitHub.com or any hosted forge. Second, it is not "unauthenticated by design." The maintainers require repository write access, and the way a stranger gets that on an exposed instance is open registration, the signup path, not a missing-auth internet-wide hole. The conditions narrow the blast radius further: it also needs Git 2.32 or newer, the diffpatch route enabled, and a writable, executable temp filesystem for the service account. Those are the facts a defender needs to gauge exposure, and they are the facts the "unauthenticated RCE" headlines drop.

The clock: an August 28 federal deadline on a fix that shipped July 28

The why-now is the calendar, not a new exploit. CISA added the CVE on August 25 and gave Federal Civilian Executive Branch agencies until August 28, a three-day window that is the tightest part of this story. Everyone outside government inherits no legal deadline, but the same date is the sane target.

The number the wire headlines skip is the age of the fix. Gitea patched this in 1.27.1 on July 28, the same day the advisory went out, and the current release is 1.27.2 (Help Net Security). So CISA's listing lands 28 days after the patch, which makes this exploitation catching up to a month-old fix rather than a zero-day scramble. If you upgraded in late July you are already clear; if you have not touched the box since, you have been exposed for a month. Gitea is the same class of self-hosted developer platform as the GitLab instances that shipped a critical GraphQL fix earlier this cycle, and the pattern rhymes: a patched forge bug, exploited before administrators moved.

The attribution CISA did not make: one Habr report, not a named campaign

Here is the gap the scary headlines paper over. SecurityWeek is blunt that "there do not appear to be any previous reports describing exploitation of CVE-2026-60004," and that "it's currently unclear who is behind the attacks and what their goal is." CISA named no campaign because it has none to name.

The vivid detail that a scanner registered an account, spun up a repository and dropped a cryptominer-type payload inside an unprivileged Docker container in about eleven seconds comes from a single incident report on the Russian blog Habr, one operator's account of one compromised self-hosted instance. Help Net Security frames it exactly that way, as a lone report rather than CISA attribution, and the Gitea maintainers keep their own description dry: "an attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user." Two more claims do not survive contact with the primary sources: calling this an "unauthenticated RCE" contradicts the maintainers, who require write access, and Security Affairs spliced an unrelated Oracle HTTP Server and WebLogic line onto this CVE that does not belong to CVE-2026-60004 at all.

The takeaway

If you run an internet-facing self-hosted Gitea between 1.17 and 1.27.0, upgrade to 1.27.1 or later now, with 1.27.2 as the current build; federal agencies are bound to August 28, and everyone else should treat that as the line rather than the suggestion. Before or alongside the upgrade, cut the precondition the flaw depends on: turn off or restrict open registration and audit who holds repository write access, because that access, not a missing password, is what the bug needs. Do not price this as a CISA-named cryptomining campaign or an unauthenticated internet-wide RCE. It is a write-access code-injection bug on a server you host, added to KEV a month after its fix, and the eleven-second miner story is one Habr report worth treating as a canary, not as CISA's attribution.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free