AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

A security vulnerability in Gitea, CVE-2026-60004, is being actively exploited by attackers. The flaw allows malicious code injection via the diffpatch API, enabling remote code execution. Authorities have added it to the CISA Known Exploited Vulnerabilities catalog, emphasizing its severity.

Security authorities have confirmed that the CVE-2026-60004 vulnerability in Gitea is currently being exploited by attackers. The flaw allows malicious actors with repository write access to inject code that can execute shell commands, posing a serious threat to affected systems. You can learn more about command injection vulnerabilities and their exploitation. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, highlighting its active exploitation and potential impact.

The CVE-2026-60004 vulnerability resides in Gitea, an open-source Git hosting platform widely used for source code management. According to CISA, attackers exploit the flaw by sending a malicious patch through the diffpatch API endpoint. This allows them to plant a malicious Git hook that can execute arbitrary shell commands on the server. The vulnerability requires the attacker to have repository write access, which is often granted to collaborators or trusted users, but it can be exploited in environments where access controls are weak or misconfigured.

Security researchers have observed active exploitation campaigns targeting vulnerable Gitea instances, with attackers leveraging the flaw to gain persistent access, deploy malware, or conduct further lateral movement within networks. This highlights the importance of monitoring for command injection vulnerabilities across different platforms. The vulnerability was identified by security analysts in late 2025, but recent reports confirm that malicious actors are now actively exploiting it in real-world attacks. For example, see how SQL injection vulnerabilities are exploited in the wild. The vulnerability’s severity is rated high due to its potential for remote code execution and the broad use of Gitea in enterprise and open-source projects.

At a glance
breakingWhen: ongoing; active exploitation confirmed…
The developmentCybersecurity authorities confirm that the Gitea CVE-2026-60004 flaw is actively exploited, posing a significant risk to affected systems.

Why Active Exploitation of CVE-2026-60004 Matters

The active exploitation of CVE-2026-60004 represents a significant security risk for organizations relying on Gitea. Because the flaw allows attackers to inject malicious code and execute arbitrary shell commands, compromised systems could face data theft, deployment of malware, or further network infiltration. The fact that the vulnerability can be exploited with repository write access makes it particularly dangerous in collaborative environments where multiple users have such permissions. The inclusion of this vulnerability in CISA’s KEV list underscores its importance, prompting urgent patching and mitigation efforts across affected organizations.

Failure to address this flaw promptly could lead to widespread compromise, especially in organizations that use Gitea for critical development workflows. Cybersecurity experts warn that threat actors are actively scanning for vulnerable instances, increasing the risk of widespread exploitation. The vulnerability’s presence in a widely adopted platform amplifies its potential impact, making it a priority for security teams worldwide.

VPN subscription for cybersecurity

Amazon

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Gitea Vulnerability Timeline and Prior Incidents

Gitea, an open-source platform for hosting Git repositories, has grown in popularity due to its lightweight design and ease of deployment. Prior to CVE-2026-60004, the platform has experienced other security issues, but none as critical or actively exploited as this recent flaw. The vulnerability was first identified by security researchers in late 2025, following reports of unusual activity on compromised Gitea servers.

In early 2026, security teams analyzed the flaw and confirmed that it allowed code injection through the diffpatch API. The flaw’s severity was rated high, and patches were issued by Gitea maintainers shortly afterward. Despite these efforts, threat actors began exploiting the vulnerability soon after, with reports of malicious activity surfacing in March 2026. This pattern of rapid exploitation after disclosure underscores the importance of swift patching and continuous monitoring.

Historically, open-source platforms like Gitea have been targets for attackers due to their widespread use in both enterprise and community projects, often with less rigorous security controls. This incident marks a significant escalation, as threat actors are now actively exploiting known vulnerabilities in popular code hosting solutions.

“The active exploitation of CVE-2026-60004 underscores the need for immediate patching and vigilance among organizations using Gitea.”

— CISA spokesperson

Unresolved Questions About the Exploitation Campaign

While it is confirmed that CVE-2026-60004 is actively exploited, details about the scope and scale of the campaigns remain unclear. It is not yet confirmed how widespread the exploitation is, or whether specific industries or regions are targeted more heavily. Additionally, the full range of malicious payloads delivered via this vulnerability has not been publicly disclosed, and it is uncertain whether additional zero-day exploits are being leveraged in conjunction with this flaw.

Security experts continue to investigate the extent of the compromise, and organizations are advised to monitor their systems closely for signs of intrusion. The full impact and the number of affected instances are still emerging as more data becomes available from incident reports and threat intelligence feeds.

Next Steps for Mitigating the Threat and Monitoring

Organizations using Gitea are strongly advised to apply the latest security patches provided by the Gitea project immediately. Security teams should review access controls, especially repository write permissions, and implement enhanced monitoring for unusual activity related to the diffpatch API endpoint.

Cybersecurity agencies and vendors are expected to release additional guidance on detection and response strategies in the coming days. Incident response teams should prepare to handle potential breaches resulting from this vulnerability and conduct thorough audits of affected systems.

Researchers and security firms will continue to analyze the exploitation techniques used by threat actors, with the goal of developing signatures and detection rules to identify ongoing campaigns. Public alerts and updates are likely to be issued as new information becomes available.

Key Questions

What is CVE-2026-60004?

CVE-2026-60004 is a code injection vulnerability in Gitea that allows attackers with repository write access to inject malicious code via the diffpatch API, leading to remote code execution.

How are attackers exploiting this vulnerability?

Attackers exploit the flaw by sending malicious patches through the diffpatch API endpoint, planting executable Git hooks that can run shell commands on the server.

Who is at risk of being affected?

Organizations that use Gitea and grant repository write access to users are at risk, especially if access controls are weak or not properly configured.

What should organizations do now?

They should apply the latest patches from Gitea, review access permissions, and enhance system monitoring to detect potential exploitation attempts.

Is this vulnerability still being exploited?

Yes, cybersecurity authorities have confirmed ongoing active exploitation campaigns targeting vulnerable Gitea instances.

Source: kev

You May Also Like

Chinese AI Matches Mythos in Cybersecurity, Report Says

A new report states that Chinese artificial intelligence systems are now comparable to Mythos in cybersecurity capabilities, marking a significant development.

Roblox’s AI-Powered Age Verification Is a Complete Mess

Roblox’s new AI-powered age verification system launched last week is plagued with errors, misidentifications, and privacy concerns, raising safety and trust issues.

Check Point Software Surges In Global Coverage

Check Point Software experiences a surge in worldwide coverage, with 55 mentions in recent reports, highlighting increased industry interest.

What Happened To HackerOne?

HackerOne, a leading bug bounty platform, is experiencing significant operational disruptions. This report covers confirmed facts and ongoing uncertainties.