VYPR
kevPublished Aug 25, 2026· Updated Aug 27, 2026· 6 sources

CISA Adds Gitea Code Injection Vulnerability to Known Exploited Vulnerabilities Catalog

CISA has added CVE-2026-60004, a Gitea code injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog, citing active exploitation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of a new vulnerability to its catalog of Known Exploited Vulnerabilities (KEV). The vulnerability, identified as CVE-2026-60004, affects Gitea, an open-source Git service, and is categorized as a code injection flaw.

This addition to the KEV Catalog signifies that CISA has confirmed evidence of active exploitation of this vulnerability in the wild. Such vulnerabilities are frequently targeted by malicious cyber actors and pose a significant risk to organizations, particularly those within the federal enterprise.

Federal Civilian Executive Branch (FCEB) agencies are now mandated to prioritize the remediation of CVE-2026-60004 on any publicly exposed assets. This directive stems from Binding Operational Directive (BOD) 26-04, which establishes vulnerability management requirements based on risk. The BOD specifically requires agencies to address vulnerabilities listed in the KEV Catalog that grant total control of an asset post-exploitation.

BOD 26-04 also emphasizes the importance of proactive threat hunting by requiring federal agencies to check for evidence of compromise before applying patches to high-risk vulnerabilities. While the directive is specific to FCEB agencies, CISA strongly encourages all organizations to adopt a risk-based vulnerability management approach and prioritize the patching of vulnerabilities listed in the KEV Catalog.

The KEV Catalog serves as a critical resource for identifying and prioritizing the most dangerous cyber threats. CISA continuously monitors for new vulnerabilities that meet the criteria for inclusion, which includes having a confirmed CVE ID, documented evidence of exploitation, and clear mitigation guidance.

Organizations that discover an exploited vulnerability not yet listed in the KEV Catalog are encouraged to submit it for consideration through CISA's KEV Nomination Form. This collaborative approach helps ensure that the catalog remains a comprehensive and up-to-date reflection of the most pressing cybersecurity risks.

The inclusion of CVE-2026-60004 underscores the ongoing threat posed by code injection vulnerabilities and the importance of timely patching and robust vulnerability management practices across all sectors.

CISA has now issued a direct warning about the active exploitation of CVE-2026-60004, a critical remote code execution vulnerability in Gitea. This advisory specifically highlights that the flaw is being exploited in the wild, urging organizations to update their instances to version 1.27.1, which was released in late July to patch the vulnerability. Federal agencies have been given a deadline of August 28 to remediate this issue.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about the active exploitation of CVE-2026-60004, a critical remote code execution vulnerability in Gitea. Recent exploitation attempts have been observed dropping miner-like payloads, indicating a shift towards cryptojacking campaigns targeting vulnerable instances. This new information details the observed payload type and highlights the potential for financial gain by threat actors exploiting this flaw.

The critical code injection vulnerability, CVE-2026-60004, affecting Gitea has now been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. This addition confirms active exploitation in the wild, with a reported incident detailing how an attacker compromised a self-hosted Gitea instance to execute arbitrary code and deploy crypto-mining software.

The article provides further details on the exploitation vector, noting that an attacker with repository write access can plant a malicious Git hook via the diffpatch API. This allows for arbitrary shell command execution with the privileges of the Gitea service account, a critical risk for software supply chains. CISA has mandated remediation by August 28, 2026, as part of Binding Operational Directive 26-04.

The new article confirms that the critical Gitea vulnerability, CVE-2026-60004, is actively being exploited in the wild, with attackers using it to execute commands and deploy miner-like payloads. It also highlights that Gitea's default open-registration setting exacerbates the risk, and recommends disabling this feature where not needed.

Synthesized by Vypr AI