U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
ID: 7e81f9a8-af9b-57f4-8d55-6387d5d09dea
STIX ID: report--7e81f9a8-af9b-57f4-8d55-6387d5d09dea
Feed Name: Security Affairs
Threat Score
CISA added Gitea vulnerability CVE-2026-60004 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog; the flaw allows remote code execution via the diffpatch API, can be exploited by unauthenticated attackers when open registration is enabled, and has been used in at least one incident to deploy a cryptocurrency-miner-like payload. Federal agencies are required to remediate the issue by August 28, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
