Mobble
Technology · Cybersecurity · published 2026-08-26 · via BleepingComputer

CISA warns of active exploitation of critical Gitea code injection vulnerability

A critical vulnerability in Gitea, tracked as CVE-2026-60004, is being actively exploited, allowing attackers to execute arbitrary commands on vulnerable servers. The flaw can be triggered via the diffpatch endpoint by users with repository write access, and default open registration makes it accessible to unauthenticated attackers. CISA has added the bug to its Known Exploited Vulnerabilities catalog and mandated federal agencies patch within three days.

Read the full article at BleepingComputer →
Related stories
CISA mandates three-day patch for exploited Zimbra vulnerability · Cybersecurity
SharePoint RCE chain exploited in the wild after PoC release · Cybersecurity
Over 270 Zimbra servers compromised in ongoing RCE attacks · Cybersecurity
WordPress Avada theme chain allows unauthenticated code execution · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Hackers now exploit critical Gitea flaw in code injection attacks.” Browse more stories.