Over 8,300 Gitea servers vulnerable to code execution attacks
ID: 0c53c325-ec39-5cd9-a897-3c88fe39982e
STIX ID: report--0c53c325-ec39-5cd9-a897-3c88fe39982e
Feed Name: Bleeping Computer
Threat Score
A critical Gitea code-injection vulnerability (CVE-2026-60004) is being actively exploited in the wild: attackers can submit malicious patches via the diffpatch endpoint to run arbitrary shell commands as the Gitea service user. Shadowserver reported ~8,393 exposed, unpatched instances; attackers have been observed deploying cryptocurrency-mining malware, and CISA has added the flaw to its catalog of actively exploited vulnerabilities and ordered urgent patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
