Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
ID: 7d7bba9e-47d5-56d1-8d9a-4aab5ae0e42f
STIX ID: report--7d7bba9e-47d5-56d1-8d9a-4aab5ae0e42f
Feed Name: Help Net Security
Gitea CVE-2026-60004 is a critical remote code execution vulnerability in the diffpatch endpoint that allows repository-controlled content to install and run Git hooks, enabling arbitrary shell command execution as the Gitea OS user; it has been exploited in the wild to deploy crypto-mining payloads. Administrators are urged to upgrade to the fixed version (1.27.2), disable open registration, rotate secrets, and harden container networking; CISA has added the flaw to its Known Exploited Vulnerabilities catalog and mandated patching for federal civilian agencies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
