Over 8,300 Gitea servers vulnerable to code execution attacks
What happened
Shadowserver identified 8,393 internet-exposed Gitea instances remaining vulnerable to CVE-2026-60004, a code injection flaw that allows attackers to execute arbitrary shell commands via the diffpatch API. The vulnerability is currently being exploited in the wild to deploy cryptocurrency mining malware, prompting CISA to mandate that federal agencies patch their servers by August 28.
Why it ranks #1
Shadowserver identified 8,393 internet-exposed Gitea instances vulnerable to CVE-2026-60004, a code injection flaw in the diffpatch API that allows arbitrary shell command execution and is currently being exploited in the wild to deploy cryptocurrency mining malware.
Who should care
Application security teams, IT and platform operations, SOC and incident response teams
What to do
"With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository.
- Impact
- high
- Urgency
- immediate
- Confidence
- high
- Scope
- product
- Status
- disclosed