Более 8300 серверов Gitea уязвимы перед выполнением произвольного кода
Researchers have confirmed active exploitation of a critical remote code execution flaw, CVE-2026-60004, affecting over 8,300 internet-facing Gitea servers worldwide. The vulnerability allows attackers with write access to repositories to execute arbitrary shell commands by injecting malicious Git hooks through the diffpatch API endpoint.
Although authentication is required for exploitation, many default configurations permit open registration, making it easy for threat actors to gain entry without stolen credentials. Gitea released a fix in version 1.27.1 on July 27, 2026, but thousands of systems remain unpatched despite CISA adding the bug to its Known Exploited Vulnerabilities catalog.