CISA Adds Gitea Code Injection Vulnerability to Known Exploited Vulnerabilities Catalog
CISA has added CVE-2026-60004, a Gitea code injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog, citing active exploitation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of a new vulnerability to its catalog of Known Exploited Vulnerabilities (KEV). The vulnerability, identified as CVE-2026-60004, affects Gitea, an open-source Git service, and is categorized as a code injection flaw.
This addition to the KEV Catalog signifies that CISA has confirmed evidence of active exploitation of this vulnerability in the wild. Such vulnerabilities are frequently targeted by malicious cyber actors and pose a significant risk to organizations, particularly those within the federal enterprise.
Federal Civilian Executive Branch (FCEB) agencies are now mandated to prioritize the remediation of CVE-2026-60004 on any publicly exposed assets. This directive stems from Binding Operational Directive (BOD) 26-04, which establishes vulnerability management requirements based on risk. The BOD specifically requires agencies to address vulnerabilities listed in the KEV Catalog that grant total control of an asset post-exploitation.
BOD 26-04 also emphasizes the importance of proactive threat hunting by requiring federal agencies to check for evidence of compromise before applying patches to high-risk vulnerabilities. While the directive is specific to FCEB agencies, CISA strongly encourages all organizations to adopt a risk-based vulnerability management approach and prioritize the patching of vulnerabilities listed in the KEV Catalog.
The KEV Catalog serves as a critical resource for identifying and prioritizing the most dangerous cyber threats. CISA continuously monitors for new vulnerabilities that meet the criteria for inclusion, which includes having a confirmed CVE ID, documented evidence of exploitation, and clear mitigation guidance.
Organizations that discover an exploited vulnerability not yet listed in the KEV Catalog are encouraged to submit it for consideration through CISA's KEV Nomination Form. This collaborative approach helps ensure that the catalog remains a comprehensive and up-to-date reflection of the most pressing cybersecurity risks.
The inclusion of CVE-2026-60004 underscores the ongoing threat posed by code injection vulnerabilities and the importance of timely patching and robust vulnerability management practices across all sectors.