logo

CVE-2026-60004: Critical Gitea RCE Exploited to Deploy Miner-Like Payloads

ID: d4dd5a65-c9e7-5d0f-bed8-00a6a0b26708

STIX ID: report--d4dd5a65-c9e7-5d0f-bed8-00a6a0b26708

Feed Name: SOC Prime Blog

Threat Score
88/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: SOC Prime Team

...
...

A critical RCE in Gitea (CVE-2026-60004, CVSS 9.8) allows authenticated users with repository write access to craft patches that become executable Git hooks and run arbitrary commands as the Gitea service account; the flaw affects Gitea 1.17 through 1.27.0 and was fixed in 1.27.1. CISA added the vulnerability to its KEV catalog after public disclosure and at least one real-world compromise that deployed a miner-like dropper; a public PoC and detection signatures exist, increasing exploitation risk. Immediate actions recommended are upgrading to 1.27.1+, disabling public registration where unnecessary, auditing for suspicious diffpatch activity and unexpected processes, and rotating exposed credentials if compromise is suspected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.