logo

Hackers now exploit critical Gitea flaw in code injection attacks

ID: 6d475195-cd55-5e65-a8f8-d353a29414b8

STIX ID: report--6d475195-cd55-5e65-a8f8-d353a29414b8

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Sergiu Gatlan

...
...

A critical Gitea code-injection vulnerability (CVE-2026-60004) in the diffpatch API enables command execution as the Gitea service account and can be triggered by unauthenticated attackers on default installations; active exploitation deploying cryptocurrency miners has been observed, prompting CISA to add the flaw to its KEV catalog and order immediate patching while Shadowserver reports nearly 5,000 exposed instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.