importantSYS.SOURCE: The Hacker News• 2026-08-26T11:57:07+05:30
Critical Gitea RCE Vulnerability CVE-2026-60004 Actively Exploited with Cryptojacking Payload
A critical remote code execution vulnerability (CVE-2026-60004) in Gitea is actively exploited, enabling attackers to deploy cryptojacking payloads through repository write access. CISA has added the flaw to its KEV catalog, urging urgent patching of affected instances.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea.
The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the
*** END OF TRANSMISSION ***