CISA added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog after confirming exploitation of a code-injection flaw in the Gitea self-hosted development platform. An attacker with repository write access can send a malicious patch to the diffpatch API, install an executable Git hook, and run shell commands under the Gitea service account. Gitea addressed the vulnerability in version 1.27.1; CISA set an August 28 remediation deadline for U.S. federal agencies and advised affected organizations to apply vendor mitigations, assess internet exposure, and conduct relevant forensic triage. The responsible threat actors and their objectives remain unknown.
CISA's preceding catalog update also added CVE-2026-21962, an improper access-control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. The Oracle flaw can permit unauthorized creation, deletion, modification, or access to critical data, potentially extending to all accessible product data. Organizations should prioritize patching or applying vendor mitigations for both KEV-listed vulnerabilities, and discontinue affected products where mitigations are unavailable.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
Shadowserver reported that 8,393 Internet-exposed Gitea IP addresses remained vulnerable to CVE-2026-60004. It also stated that exploitation attacks against the flaw were ongoing.
CISA added CVE-2026-60004 to the KEV Catalog, identifying known exploitation of the Gitea code-injection vulnerability. The flaw requires repository write access and can be exploited through the diffpatch API to install an executable Git hook and run shell commands under the Gitea service account.
CISA added CVE-2026-21962, an improper access control flaw affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities Catalog. The flaw can enable unauthorized access to or modification of critical data, including complete access to accessible product data.
Independent security researchers published a working exploit tool for CVE-2026-60004. The tool operationalized exploitation of the Gitea diffpatch code-injection flaw to execute commands as the Gitea service account.
Gitea issued its formal security advisory for CVE-2026-60004, following the release of version 1.27.1 that fixed the critical diffpatch remote code-execution flaw.
Gitea released version 1.27.1, patching CVE-2026-60004, a vulnerability that can let a repository writer install a malicious Git hook and execute commands as the Gitea service account.
Organizations were warned that the separate Gitea vulnerability CVE-2026-20896 was being exploited in the wild. It had not been added to CISA's KEV Catalog at the time of the report.
Developer Andrey (@Causelof) reported that an unknown actor exploited CVE-2026-60004 against their HTTPS-exposed Gitea instance, deploying a miner-like dropper and causing sustained CPU utilization above 70%. The next-stage payload, mining pool, wallet, and operator were not identified.
A public proof of concept described exploitation of Gitea's diffpatch API by using a crafted patch to place a malicious Git hook in a temporary repository. Later Git operations can execute the hook as the Gitea service account, requiring an authenticated account with repository write access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
21 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcetriskelelabs.com
Open sourcecybersecuritynews.com
Open sourceboho.or.kr
Open sourcegithub.com
Open sourceblog.gitea.com
Open sourcedocs.docker.com
Open sourcecyber.dhs.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.