logo

Over 8,300 Gitea servers vulnerable to code execution attacks

ID: 0c53c325-ec39-5cd9-a897-3c88fe39982e

STIX ID: report--0c53c325-ec39-5cd9-a897-3c88fe39982e

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

Author: Sergiu Gatlan

...
...

A critical Gitea code-injection vulnerability (CVE-2026-60004) is being actively exploited in the wild: attackers can submit malicious patches via the diffpatch endpoint to run arbitrary shell commands as the Gitea service user. Shadowserver reported ~8,393 exposed, unpatched instances; attackers have been observed deploying cryptocurrency-mining malware, and CISA has added the flaw to its catalog of actively exploited vulnerabilities and ordered urgent patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.