Critical Gitea Vulnerability CVE-2026-60004 Actively Exploited

Critical Gitea Vulnerability CVE-2026-60004 Actively Exploited

First seen 26 Aug 2026, 12:52 UTC Feeds2.FeedburnerBleepingcomputerblog.gitea.comgithub.com 72.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability in Gitea, tracked as CVE-2026-60004, is being actively exploited by attackers, allowing unauthorized users to execute arbitrary shell commands on vulnerable servers. This flaw affects self-hosted Gitea instances, particularly those with default configurations that permit self-registration. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to secure their servers by August 28, 2026. Gitea released version 1.27.1 on July 27, 2026, to patch this vulnerability. Reports indicate that attackers are deploying cryptocurrency mining malware on unpatched servers. CISA has emphasized the significant risks posed by this vulnerability to federal enterprises. Additionally, another critical vulnerability, CVE-2026-20896, was previously exploited in July 2026, indicating ongoing security challenges for Gitea users.

Key Points: • CVE-2026-60004 allows arbitrary command execution on vulnerable Gitea instances. • CISA has mandated federal agencies to secure their Gitea servers by August 28, 2026. • Gitea version 1.27.1 was released to address this critical vulnerability.

Timeline

2026-07-03
CVE-2026-20896 published
A critical authentication bypass vulnerability in Gitea was disclosed.
Bleepingcomputer
2026-07-27
Gitea 1.27.1 released
Gitea released version 1.27.1 to patch CVE-2026-60004 and other vulnerabilities.
blog.gitea.com
2026-08-26
CISA adds CVE-2026-60004 to KEV catalog
CISA confirmed active exploitation of the vulnerability and mandated action for federal agencies.
Bleepingcomputer
2026-08-26
Active exploitation confirmed
Reports indicate attackers are deploying cryptocurrency mining malware on unpatched Gitea servers.
Feeds2.Feedburner