CVE Tools
Back to feed
Exploited in the wild Gitea rce zero-day

Более 8300 серверов Gitea уязвимы перед выполнением произвольного кода

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Researchers have confirmed active exploitation of a critical remote code execution flaw, CVE-2026-60004, affecting over 8,300 internet-facing Gitea servers worldwide. The vulnerability allows attackers with write access to repositories to execute arbitrary shell commands by injecting malicious Git hooks through the diffpatch API endpoint.

Although authentication is required for exploitation, many default configurations permit open registration, making it easy for threat actors to gain entry without stolen credentials. Gitea released a fix in version 1.27.1 on July 27, 2026, but thousands of systems remain unpatched despite CISA adding the bug to its Known Exploited Vulnerabilities catalog.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store