Remote Code Execution Vulnerability in Gitea by Gitea
CVE-2026-60004

9.8CRITICAL

Key Information:

Vendor

Gitea

Status
Vendor
CVE Published:
26 August 2026

Badges

📈 Trended📈 Score: 3,890💰 Ransomware👾 Exploit Exists🟡 Public PoC🟣 EPSS 86%🦅 CISA Reported📰 News Worthy

What is CVE-2026-60004?

CVE-2026-60004 is a significant vulnerability found in Gitea, an open-source self-hosted Git service known for providing a simple and easy-to-use interface for managing Git repositories. The vulnerability allows for remote code execution via the diffpatch API, leveraging Git hook installation. This means that an attacker could potentially execute arbitrary code on the server, leading to a complete compromise of the affected system. Given that Gitea is used by various organizations for source code management and collaboration, this vulnerability can severely impact the confidentiality, integrity, and availability of sensitive code and data.

Potential Impact of CVE-2026-60004

  1. Unauthorized System Access: The remote code execution capability of this vulnerability allows attackers to gain unauthorized access to the underlying server, which can lead to complete system takeover and manipulation of files and settings.

  2. Data Breach Risk: Exploitation of this vulnerability may result in the exposure of sensitive code and data housed within the Gitea instances, potentially leading to significant data breaches that could compromise proprietary or confidential information.

  3. Widespread Malware Dissemination: With the ability to execute arbitrary code, attackers can deploy malware or ransomware on the affected systems, which might also facilitate lateral movement within an organization’s network, thereby exacerbating the overall security threat.

CISA has reported CVE-2026-60004

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-60004 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

Gitea 1.17 < 1.27.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

Red Heron exploited Gitea CVE-2026-60004 to steal repositories, collect credentials, persist, and move laterally across victim networks

1 week ago

Over 8,300 Gitea servers vulnerable to code execution attacks

Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver.

3 weeks ago

CISA Confirms Gitea CVE-2026-60004 Exploited: Cryptominer Hits 5,000 Exposed Dev Servers

Gitea CVE-2026-60004, a CVSS 9.8 code-injection flaw, is now on CISA’s Known Exploited Vulnerabilities list after attackers deployed cryptocurrency-mining malware on unpatched dev servers. Federal

4 weeks ago

References

EPSS Score

86% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 💰

    Used in Ransomware

  • 📈

    Vulnerability started trending

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • 🦅

    CISA Reported

  • 📰

    First article discovered by The Hacker News

  • Vulnerability Reserved

.