logo

U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog

ID: 7e81f9a8-af9b-57f4-8d55-6387d5d09dea

STIX ID: report--7e81f9a8-af9b-57f4-8d55-6387d5d09dea

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Pierluigi Paganini

...
...

CISA added Gitea vulnerability CVE-2026-60004 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog; the flaw allows remote code execution via the diffpatch API, can be exploited by unauthenticated attackers when open registration is enabled, and has been used in at least one incident to deploy a cryptocurrency-miner-like payload. Federal agencies are required to remediate the issue by August 28, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.