CVE Tools
Back to feed
Exploited in the wild Gitea rce malware

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Help Net Security·By Zeljka Zorz··3 min read
CVE Tools coverage

CISA has confirmed active exploitation of CVE-2026-60004, a critical code injection flaw in the Gitea Git platform, listing it in its Known Exploited Vulnerabilities catalog. Attackers leverage the diffpatch endpoint to execute arbitrary shell commands, allowing them to deploy cryptocurrency miners on self-hosted instances where open registration is enabled. A detailed incident report highlights how automated scanners compromised outdated deployments within seconds, granting access to sensitive configuration files and environment variables. Administrators are advised to immediately upgrade to Gitea v1.27.2, disable unauthenticated account creation, and rotate all exposed secrets.