Exploited in the wild Gitea rce web-app
Over 8,300 Gitea servers vulnerable to code execution attacks
CVE Tools coverage
Shadowserver reports that over 8,300 internet-facing Gitea instances remain vulnerable to active remote code execution attacks exploiting CVE-2026-60004. This code injection flaw allows attackers with repository write access—or anyone able to exploit default open registration—to execute arbitrary shell commands via the diffpatch API endpoint. Although Gitea released version 1.27.1 on July 27 to remediate the issue, CISA has since added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated immediate patching for federal agencies.
Recent activity suggests threat actors are leveraging this weakness to deploy cryptocurrency mining malware on compromised systems.