Start your day with intelligence. Get The OODA Daily Pulse.

Home > Briefs > Cyber > CISA Warns of Exploited Gitea Vulnerability

CISA Warns of Exploited Gitea Vulnerability

CISA warns of active exploitation of Gitea code‑injection flaw.

CISA says attackers are exploiting CVE‑2026‑60004, a Gitea code‑injection bug that allows anyone with repository write access to plant executable Git hooks and run commands as the service account. The flaw, patched in version 1.27.1, has been added to the KEV catalog with federal agencies ordered to update by August 28. Details on the attackers or their motives remain unclear, though another Gitea flaw, CVE‑2026‑20896, was also recently seen in the wild. Organizations using the self‑hosted platform are urged to apply patches promptly given the active exploitation.

Read more:

https://www.securityweek.com/cisa-warns-of-exploited-gitea-vulnerability/