MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-08-26 · via BleepingComputer

CISA warns of active exploitation of critical Gitea code injection vulnerability

Image via BleepingComputer
Image via BleepingComputer

A critical vulnerability in Gitea, tracked as CVE-2026-60004, is being actively exploited, allowing attackers to execute arbitrary commands on vulnerable servers. The flaw can be triggered via the diffpatch endpoint by users with repository write access, and default open registration makes it accessible to unauthenticated attackers. CISA has added the bug to its Known Exploited Vulnerabilities catalog and mandated federal agencies patch within three days.

Expanded Detail

EXPANDED:

The vulnerability was discovered

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
CISA Adds Five Flaws to KEV Catalog After Flax Typhoon Attacks · Cybersecurity
SonicWall SMA1000 vulnerability exploited shortly after patch · Cybersecurity
Citrix Discloses Severe NetScaler Flaw Allowing Remote Code Execution · Cybersecurity
Google Health 5.10 update arrives with three new features · Software & cloud
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Hackers now exploit critical Gitea flaw in code injection attacks.” Browse more stories.