CISA says attackers are exploiting a critical Gitea code-injection flaw
CISA says CVE-2026-60004 is being exploited on self-hosted Gitea: a critical code injection in the diffpatch API. Default open registration lets an unauthenticated visitor create an account and repository, then run commands as the gitea user.

On August 26, 2026 BleepingComputer reported that attackers are exploiting a critical Gitea flaw that CISA has now flagged.
What we know
- CISA says CVE-2026-60004 is being exploited on self-hosted Gitea as a critical code injection in the diffpatch API.
- Default open registration lets an unauthenticated visitor create an account and repository, then run commands as the gitea user.
- The flaw was fixed in Gitea 1.27.1 on July 27 after a report by Salesforce’s Shai Rod.
- Federal civilian agencies have a patch deadline of August 28 under BOD 26-04.
- Shadowserver has seen about 5,000 exposed instances; some attacks deployed cryptocurrency miners.
Takeaways
- Open registration turns an unauthenticated visitor into a command-running gitea user.
- The fix shipped in 1.27.1 on July 27; CISA now wants civilian agencies patched by August 28.
- Thousands of instances are still exposed, and some exploitation has dropped miners.
Source: BleepingComputer / CISA


