Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. 🔴 Critical: Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

🔴 Critical: Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
cve-2026-60004
1 Posts 1 Posters 2 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Gitea vulnerability to its Known Exploited Vulnerabilities catalog following confirmed reports of active exploitation in the wild. The flaw, tracked as CVE-2026-60004 with a CVSS score of 9.8, is a remote code execution vulnerability.

    An attacker who possesses ordinary write access to a repository can exploit this issue to execute arbitrary shell commands on the underlying server. This effectively allows a low-privileged user to escalate their access to full system-level control, making the bug particularly dangerous for self-hosted instances of the popular Git service.

    Given the severity and the confirmed exploitation, administrators are urged to verify their current Gitea version and apply the latest security patches immediately if they have not already done so. It is also recommended to audit repository access controls and review system logs for any unusual command execution or unauthorized changes.

    • Verify your Gitea version against the latest patched release.
    • Restrict write access to repositories to only trusted users.
    • Monitor server logs for the execution of unexpected shell commands.

    Source: The Hacker News

    Are you running a self-hosted Gitea instance, and have you had to lock down repository write permissions as an immediate mitigation before patching?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World