Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
What happened
CISA added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog, though the agency did not disclose whether this action resulted from the specific reported attack or other evidence of exploitation. The vulnerability allows attackers with repository write access to execute arbitrary shell commands via the diffpatch endpoint, a risk amplified by Gitea’s default open registration setting. A reported incident involved an unknown threat actor using this flaw to deploy a cryptocurrency-miner-like dropper on a compromised instance.
Why it ranks #1
CISA added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog, though the agency did not disclose whether this action resulted from the specific reported attack or other evidence of exploitation.
Who should care
Application security teams, IT and platform operations, SOC and incident response teams
What to do
Federal agencies must patch the flaw by August 28, 2026, prioritizing updates based on a risk-based approach.
- Impact
- moderate
- Urgency
- immediate
- Confidence
- high
- Scope
- product
- Status
- actively exploited