News

CISA adds Gitea CVE-2026-60004 to KEV, federal deadline August 28

CISA added one self-hosted Gitea flaw, CVE-2026-60004 (CWE-94 code injection, CVSS 9.8), to its Known Exploited Vulnerabilities catalog on August 25, with a federal remediation deadline of August 28 under BOD 26-04. It was fixed in Gitea 1.27.1 back on July 28 (latest is 1.27.2), it needs repository write access rather than being unauthenticated by design, and CISA lists no threat actor and ransomware use as Unknown. The cryptominer-in-Docker story traces to a single Habr incident report, not to CISA.

CISA adds Gitea CVE-2026-60004 to KEV, federal deadline August 28

CISA added a single Gitea vulnerability, CVE-2026-60004, to its Known Exploited Vulnerabilities catalog on August 25 and set a federal remediation deadline of August 28 under Binding Operational Directive 26-04. The CISA alert and the KEV catalog say the flaw is being exploited in the wild and put agencies on a three-day clock. The listing names no threat actor, no malware and no victim count, and marks ransomware use as Unknown.

Per the Gitea advisory GHSA-rcr6-4jqh-j84m, published July 28, CVE-2026-60004 is a CWE-94 code injection rated CVSS 9.8. SecurityWeek quotes CISA's own characterization: "Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account."

The bug hits self-hosted Gitea >=1.17 and <1.27.1, the software teams install on their own servers, not GitHub.com or any hosted forge. The maintainers require repository write access. On an exposed instance, a stranger typically gets that through open registration, the signup path, rather than a missing-auth hole that works against the whole internet.

The conditions narrow further: the attack also needs Git 2.32 or newer, the diffpatch route enabled, and a writable, executable temp filesystem for the service account. Headlines that call this unauthenticated remote code execution drop those constraints.

CISA added the CVE on August 25 and gave Federal Civilian Executive Branch agencies until August 28. Everyone outside government inherits no legal deadline.

Gitea patched this in 1.27.1 on July 28, the same day the advisory went out, and the current release is 1.27.2 (Help Net Security). CISA's listing lands 28 days after the patch, which makes this exploitation catching up to a month-old fix rather than a zero-day scramble. Gitea is the same class of self-hosted developer platform as the GitLab instances that shipped a critical GraphQL fix earlier this cycle: a patched forge bug, exploited before administrators moved.

SecurityWeek is blunt that "there do not appear to be any previous reports describing exploitation of CVE-2026-60004," and that "it's currently unclear who is behind the attacks and what their goal is."

The vivid detail that a scanner registered an account, spun up a repository and dropped a cryptominer-type payload inside an unprivileged Docker container in about eleven seconds comes from a single incident report on the Russian blog Habr, one operator's account of one compromised self-hosted instance. Help Net Security frames it as a lone report rather than CISA attribution. The Gitea maintainers keep their own description dry: "an attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user."

Two more claims do not match the primary sources. Calling this an unauthenticated RCE contradicts the maintainers, who require write access. Security Affairs spliced an unrelated Oracle HTTP Server and WebLogic line onto this CVE that does not belong to CVE-2026-60004 at all.

Some offers on this page may be paid placements or contain affiliate links.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free