CISA is warning organizations that a recently patched Gitea vulnerability allowing remote code execution is being exploited in the wild.
Gitea is a widely used open source, self-hosted software development platform that provides Git hosting, code review, team collaboration, and CI/CD capabilities.
Tracked as CVE-2026-60004, the exploited vulnerability was patched by Gitea developers in late July with the release of version 1.27.1.
CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog and instructed federal agencies to patch it by August 28.
“Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account,” the cybersecurity agency explained.
There do not appear to be any previous reports describing exploitation of CVE-2026-60004. It’s currently unclear who is behind the attacks and what their goal is.
This is not the only Gitea vulnerability exploited in the wild in recent months. In early July, organizations were warned about the exploitation of a different flaw, CVE-2026-20896.
It’s worth noting that CVE-2026-20896 has yet to be added to CISA’s KEV catalog.
Related: Gitea Vulnerability Exposed 30,000 Deployments to Attacks
Related: WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
Related: CISA Warns of Exploited Oracle WebLogic Vulnerability


