CVE-2026-60004
Published Aug 26, 2026
Last updated 17 days ago
AI description
CVE-2026-60004 is a remote code execution (RCE) vulnerability found in Gitea, an open-source, self-hosted Git service. This code injection flaw allows an attacker with repository write access to exploit the `diffpatch` API endpoint. By sending a malicious patch, the attacker can plant an executable Git hook, which then enables them to execute arbitrary shell commands using the privileges of the Gitea service account. The vulnerability affects Gitea versions 1.17 through 1.27.0 and was addressed in version 1.27.1. The Cybersecurity and Infrastructure Security Agency (CISA) has included CVE-2026-60004 in its Known Exploited Vulnerabilities catalog, confirming its active exploitation. In configurations where open self-registration is enabled, an unauthenticated individual can obtain the necessary repository write access by simply registering an account and creating a repository.
- Description
- Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
- Source
- cve@mitre.org
- NVD status
- Analyzed
- Products
- gitea
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Gitea Code Injection Vulnerability
- Exploit added on
- Aug 25, 2026
- Exploit action due
- Aug 28, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- cve@mitre.org
- CWE-94
- Hype score
- Not currently trending
Vulnerabilità Gitea CVE-2026-60004: come mettere in sicur… La vulnerabilità Gitea CVE-2026-60004 richiede una verifica rapida dei server che espongono… https://t.co/yc0f9jimvY #Sicurezza #OCEWeb https://t.co/qVW8XBRIin
@oceweb
3 Sept 2026
51 Impressions
3 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Qwen asks builders for real-world workflows. We gave Qwen3.8-Flash-Next one: investigate a critical CVE end to end, fully local. It built the lab, reproduced CVE-2026-60004, verified the fix 22/22, and shipped open detections, paper and film. @Alibaba_Qwen @QwenDevs https://t.co/
@0x00Sector
1 Sept 2026
80 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🐦 🚨 CISA KEV: CVE-2026-53362 (Linux kernel) actively exploited — OpenAI's own AI agents used it to root their systems. CVE-2026-60004 (Gitea) still hits 8,300+ unpatched servers with crypto miners. ServiceNow also fixed 3x CVSS 10.0 unauth RCE/SQLi bugs. #infosec #CVE
@ita_ipo
31 Aug 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-60004: Gitea Remote Code Execution Bug - What It Means for Your Business and How to Respond https://t.co/xJLX3e1lbM
@integ_sec
30 Aug 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
𝗖𝗿𝗶𝘁𝗶𝗰𝗮𝗹 𝗚𝗶𝘁𝗲𝗮 𝗥𝗖𝗘 𝗔𝗰𝘁𝗶𝘃𝗲𝗹𝘆 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱 𝗮𝘀 𝗥𝗲𝗽𝗼𝗿𝘁𝗲𝗱 𝗔𝘁𝘁𝗮𝗰𝗸 𝗗𝗿𝗼𝗽𝘀 𝗠𝗶𝗻𝗲𝗿-𝗟𝗶𝗸𝗲 𝗣𝗮𝘆𝗹
@ShadowSpanHQ
30 Aug 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
GiteaのCVE-2026-60004をCISAが実悪用確認、1.27.1へ更新 https://t.co/pFvNUuypoC #IT #Security #cybersecurity
@Teeeda_worker
30 Aug 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🎯 Today's top exploit risk: CVE-2026-60004 (Gitea) Actively exploited. Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. #KEV #RCE #CVE
@BytesNora
30 Aug 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Highest live exploit risk right now — CVE-2026-60004 (Gitea) Actively exploited. Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. #CVE #RCE #SecOps
@BytesNora
28 Aug 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Top CVEs w/ public exploits (Aug 27): CVE-2026-60004 Vulnerability Record: CVE-2026-60004 CVE-2026-36851 Vulnerability Record: CVE-2026-36851 Protect via https://t.co/3IVcXRXJyB
@exploitgrid
27 Aug 2026
31 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-60004 - EXPLOIT CVE-2026-65956 CVE-2026-77537 CVE-2026-77550 CVE-2026-77554 ..🧵👇
@exploitgrid
27 Aug 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🔒 #CyberSecurity CVE-2026-60004: Gitea Unauthenticated Remote Code Execution — Detection and Rem… "CISA has issued a warning regarding CVE-2026-60004, an unauthenticated code execution…" 🔗 https://t.co/sucOaC3222 #CyberSecurity #ThreatIntel #cve #zeroday #patchtue
@SecurityAr58409
27 Aug 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Legacy exposure keeps paying off for attackers. Gitea CVE-2026-60004: Patch Self-Hosted Git Before RCE Be… CISA says CVE-2026-60004 is now exploited in the wild. Gitea operators should patch, disabl… 🔗 Read → https://t.co/HYp9OqspFc
@fynn_JourX
27 Aug 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛑 Gitea CVE-2026-60004: Patch Self-Hosted Git Before RCE Becomes an Incid… CISA says CVE-2026-60004 is now exploited in the wild. Gitea operators should patch, disabl… 🔗 Details → https://t.co/4x7ICRhg2y
@lucasverdan
27 Aug 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
For defenders, gitea cve-2026-60004: patch self-hosted git before rce becomes… should move fast. CISA says CVE-2026-60004 is now exploited in the wild. Gitea operators should patch, disabl… 🔗 Details → https://t.co/Xmubfa45RA
@SocXAInvaders
27 Aug 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-60004 — Gitea RCE actively exploited Public PoC available, real-world attacks confirmed, and CISA has added it to KEV. Fixed in Gitea 1.27.1. https://t.co/jpZ0uos8Ge #CVE #Gitea #RCE #CyberSecurity #InfoSec #CISA https://t.co/kvRaZZz5I7
@stem__shop
27 Aug 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Giteaの重大な脆弱性が実際に悪用される(CVE-2026-60004) Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) #HelpNetSecurity (Aug 26) https://t.co/yPWMHEb2qA
@foxbook
27 Aug 2026
230 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Heads-up: CVE-2026-60004 is under active exploitation. Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hoo… CVSS 9.8. This belongs at the top of your patch queue. https://t.co/YW4ZQtBnLJ #CVE #RCE #ActivelyExploited
@BytesNora
26 Aug 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004): Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known… https://t.co/WH6UtVVTt
@shah_sheikh
26 Aug 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ CYBER BULLETIN | 2026/08/26 🚨 CISA flags an actively exploited Gitea RCE CISA added CVE-2026-60004 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog. With default open registration, an attacker can create an account, get repo write access, plant a Git hook via
@FrontieraTechIT
26 Aug 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🔒 #CyberSecurity CVE-2026-60004: Gitea Code Injection Exploitation — KEV Detection and Remediati… "On August 25, 2026, CISA added CVE-2026-60004 — a code injection vulnerability in Gitea,…" 🔗 https://t.co/elMZ4jv3d8 #CyberSecurity #ThreatIntel #cve #zeroday #pat
@SecurityAr58409
26 Aug 2026
35 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
Gitea'da RCE Açığı Aktif Olarak İstismar Ediliyor CVE-2026-60004 kodlu uzaktan kod çalıştırma açığı CISA'nın KEV kataloğuna eklendi. Gitea kullanıcılarının 1.27.1 veya üstüne güncellemesi kritik. #CVE #SiberGüvenlik https://t.co/cmZORo9ROT
@KubbeSiber
26 Aug 2026
12 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-60004: Gitea diffpatch Code Injection Added to CISA KEV — Detection an… "CISA added CVE-2026-60004 to the Known Exploited Vulnerabilities catalog on…" 🔗 https://t.co/GTwHqJgDW3 #CyberSecurity #ThreatIntel #cve202660004 #critical #cisakev
@SecurityAr58409
26 Aug 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ CVE-2026-60004: Vulnerabilidad Crítica de Inyección de Código en Gitea Explotada Activamente Análisis técnico de CVE-2026-60004, vulnerabilidad de inyección de código en Gitea que permite ejecutar comandos como la cuenta de servicio mediante Git hooks m https://t.c
@CiberPlanetaOrg
25 Aug 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
没被很多人提到,但已经被大规模利用的rce CVE-2026-60004 今早发现我的一台服务器中招了 攻击者在我的私人gitea注册了数千个帐号,启动数千个项目,通过hook实现以service用户运行挖矿程序 https://t.co/cqACBnd118
@galaxy1025850
16 Aug 2026
246 Impressions
0 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-60004 - Gitea Pre-Auth Remote Code Execution https://t.co/zEluml5X0J #CVE #Gitea #RCE https://t.co/BrHNeEKJlx
@d4rk_c0r3
3 Aug 2026
45 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-60004 - critical 🚨 Gitea <= 1.27.0 - Pre-Auth Remote Code Execution > Gitea versions 1.17 through 1.27.0 contain a remote code execution vulnerability in t... 👾 https://t.co/RgxA7gv1Qg @pdnuclei #NucleiTemplates #cve
@pdnuclei_bot
3 Aug 2026
56 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:*",
"matchCriteriaId": "2F773281-54C1-45F3-A53A-1638FC28E83E",
"versionEndExcluding": "1.27.1",
"versionStartIncluding": "1.17.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]