CVE-2026-60004

Zero-day
Gitea

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-60004 is a remote code execution (RCE) vulnerability found in Gitea, an open-source, self-hosted Git service. This code injection flaw allows an attacker with repository write access to exploit the `diffpatch` API endpoint. By sending a malicious patch, the attacker can plant an executable Git hook, which then enables them to execute arbitrary shell commands using the privileges of the Gitea service account. The vulnerability affects Gitea versions 1.17 through 1.27.0 and was addressed in version 1.27.1. The Cybersecurity and Infrastructure Security Agency (CISA) has included CVE-2026-60004 in its Known Exploited Vulnerabilities catalog, confirming its active exploitation. In configurations where open self-registration is enabled, an unauthenticated individual can obtain the necessary repository write access by simply registering an account and creating a repository.

Description
-

Social media

Hype score
Not currently trending
  1. Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004): Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known… https://t.co/WH6UtVVTt

    @shah_sheikh

    26 Aug 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🔒 #CyberSecurity CVE-2026-60004: Gitea Code Injection Exploitation — KEV Detection and Remediati… "On August 25, 2026, CISA added CVE-2026-60004 — a code injection vulnerability in Gitea,…" 🔗 https://t.co/elMZ4jv3d8 #CyberSecurity #ThreatIntel #cve #zeroday #pat

    @SecurityAr58409

    26 Aug 2026

    28 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Gitea'da RCE Açığı Aktif Olarak İstismar Ediliyor CVE-2026-60004 kodlu uzaktan kod çalıştırma açığı CISA'nın KEV kataloğuna eklendi. Gitea kullanıcılarının 1.27.1 veya üstüne güncellemesi kritik. #CVE #SiberGüvenlik https://t.co/cmZORo9ROT

    @KubbeSiber

    26 Aug 2026

    12 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔒 #CyberSecurity CVE-2026-60004: Gitea diffpatch Code Injection Added to CISA KEV — Detection an… "CISA added CVE-2026-60004 to the Known Exploited Vulnerabilities catalog on…" 🔗 https://t.co/GTwHqJgDW3 #CyberSecurity #ThreatIntel #cve202660004 #critical #cisakev

    @SecurityAr58409

    26 Aug 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🛡️ CVE-2026-60004: Vulnerabilidad Crítica de Inyección de Código en Gitea Explotada Activamente Análisis técnico de CVE-2026-60004, vulnerabilidad de inyección de código en Gitea que permite ejecutar comandos como la cuenta de servicio mediante Git hooks m https://t.c

    @CiberPlanetaOrg

    25 Aug 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 没被很多人提到,但已经被大规模利用的rce CVE-2026-60004 今早发现我的一台服务器中招了 攻击者在我的私人gitea注册了数千个帐号,启动数千个项目,通过hook实现以service用户运行挖矿程序 https://t.co/cqACBnd118

    @galaxy1025850

    16 Aug 2026

    246 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2026-60004 - Gitea Pre-Auth Remote Code Execution https://t.co/zEluml5X0J #CVE #Gitea #RCE https://t.co/BrHNeEKJlx

    @d4rk_c0r3

    3 Aug 2026

    45 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CVE-2026-60004 - critical 🚨 Gitea <= 1.27.0 - Pre-Auth Remote Code Execution > Gitea versions 1.17 through 1.27.0 contain a remote code execution vulnerability in t... 👾 https://t.co/RgxA7gv1Qg @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    3 Aug 2026

    56 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.