Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities SecurityWeek

CISA Warns of Exploited Gitea Vulnerability

CVE-2026-60004 is a remote code execution vulnerability in Gitea where an attacker with repository write access can send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account. The flaw was patched by Gitea developers in late July with the release of version 1.27.1, and CISA has added it to its Known Exploited Vulnerabilities catalog with a directive for federal agencies to patch by August 28.
Read Full Article →

Vulnerabilities CISA Warns of Exploited Gitea Vulnerability CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. By Eduard Kovacs | August 26, 2026 (1:17 AM ET) Flipboard Reddit Whatsapp Whatsapp Email CISA is warning organizations that a recently patched Gitea vulnerability allowing remote code execution is being exploited in the wild. Gitea is a widely used open source, self-hosted software development platform that provides Git hosting, code review, team collaboration, and CI/CD capabilities. Tracked as CVE-2026-60004, the exploited vulnerability was patched by Gitea developers in late July with the release of version 1.27.1. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog and instructed federal agencies to patch it by August 28. “Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account,” the cybersecurity agency explained. There do not appear to be any previous reports describing exploitation of CVE-2026-60004. It’s currently unclear who is behind the attacks and what their goal is. Advertisement. Scroll to continue reading. This is not the only Gitea vulnerability exploited in the wild in recent months. In early July, organizations were warned about the exploitation of a different flaw, CVE-2026-20896 . It’s worth noting that CVE-2026-20896 has yet to be added to CISA’s KEV catalog. Related : Gitea Vulnerability Exposed 30,000 Deployments to Attacks Related : WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Related : CISA Warns of Exploited Oracle WebLogic Vulnerability Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs CISA Warns of Exploited Oracle WebLogic Vulnerability ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited 91 Vulnerabilities Patched in Spring Application Framework Venezuelan Gets Record Federal Prison Term for ATM Jackpotting Personal Information Exposed in Apollo Global Data Breach Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind Latest News Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference First Malware Built Specifically for Car Head Units Fuels Botnet Silent Patches Don’t Stop Attackers – They Blind Defenders Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the Move Devi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital. Forcepoint has named Proofpoint veteran Vincent Merlin as its new Chief Marketing Officer. Vensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer. More People On The Move Expert Insights Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email

Share this article