Over 8,300 Gitea servers vulnerable to code execution attacks

Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea servers remain unpatched against CVE-2026-60004, a critical code injection flaw that is being actively exploited for remote code execution. CISA and Shadowserver have urged urgent patching after reports of attackers using the issue to deploy cryptocurrency mining malware on vulnerable systems. #Gitea #CVE-2026-60004 #Shadowserver #CISA

Keypoints

  • More than 8,300 exposed Gitea instances are still vulnerable.
  • CVE-2026-60004 allows arbitrary shell command execution through the diffpatch API.
  • Open registration can let unauthenticated attackers gain write access and exploit the flaw.
  • Gitea fixed the issue in version 1.27.1 and urged immediate upgrades.
  • CISA added the flaw to its actively exploited catalog and ordered federal agencies to patch quickly.

Read More: https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/