CVE-2026-60004
Description
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
In plain language
AI Act nowCVE-2026-60004 is a serious Gitea flaw that lets an attacker run code on your server without logging in; if you run Gitea before 1.27.1, you should treat this as an urgent compromise risk.
CVE-2026-60004 is unauthenticated remote code execution in Gitea (diffpatch API) caused by allowing an attacker to install malicious Git hooks, leading to arbitrary command execution on the server; this is listed in CISA KEV with confirmed exploitation.
What to do now
- Check your Gitea version and confirm it is earlier than 1.27.1.
- Upgrade Gitea to 1.27.1 or later immediately.
- If you cannot upgrade right away, apply the vendor-recommended mitigations/workarounds from the Gitea security advisory and immediately limit/disable public access to the diffpatch API as feasible.
- Review Gitea server logs for signs of hook installation or suspicious processes, and investigate any indicators of compromise.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Chinese hackers exploit WordPress, Zyxel flaws to steal govt dataen-us·BleepingComputer· Exploited WordPress Red Heron
- Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)en-us·Help Net Security· Exploited ZyXEL GS1900 data-breach
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countriesen·The Hacker News· Exploited Gitea Red Heron
- Более 8300 серверов Gitea уязвимы перед выполнением произвольного кодаru-ru·Хакер (xakep.ru)· Exploited Gitea rce
- Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploiteden-us·Help Net Security· Exploited Zimbra ShinyHunters
- Over 8,300 Gitea servers vulnerable to code execution attacksen-us·BleepingComputer· Exploited Gitea rce
- Hackers now exploit critical Gitea flaw in code injection attacksen-us·BleepingComputer· Exploited Gitea rce
- Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)en-us·Help Net Security· Exploited Gitea rce
- Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payloaden·The Hacker News· Exploited Gitea rce
- CISA Warns of Exploited Gitea Vulnerabilityen-us·SecurityWeek· Exploited Gitea rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-60004 and every CVE in our database. Create a free account — no credit card required.
Create Free Account