CVE Tools
Back to feed
Exploited in the wild Gitea rce malware

Hackers now exploit critical Gitea flaw in code injection attacks

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

CISA has confirmed that attackers are actively using a critical code injection vulnerability in Gitea to deploy cryptocurrency mining malware on self-hosted servers. Tracked as CVE-2026-60004, this flaw allows authenticated users with repository write access—and effectively any unregistered attacker due to default open registration—to execute arbitrary shell commands through the diffpatch API endpoint. The agency added the issue to its Known Exploited Vulnerabilities catalog and mandated federal civilian executive branch agencies apply fixes by August 28. Users should upgrade to Gitea version 1.27.1 immediately to mitigate these attacks.