Cyber Resilience
← All news
Corroborated

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Our takeCISA added CVE-2026-60004 to its KEV catalog: this critical code injection flaw in Gitea is confirmed exploited in the wild. Patch immediately if you run a self-hosted instance.
Sources (2)
What this means for you — Security leader:Patch Gitea to a version containing the fix for CVE-2026-60004 immediately if you self-host it; this code injection flaw is confirmed exploited in the wild.
What this means for you — Lean IT orgs:If you run your own Gitea server, update it to the latest version right away; attackers are already using this critical code injection flaw against exposed instances.
What this means for you — MSP:Check every client that self-hosts Gitea and ensure they are updated past CVE-2026-60004; the vulnerability is confirmed exploited in the wild.
What this means for you — Researcher:CISA added CVE-2026-60004 (critical code injection in Gitea) to its KEV catalog; exploitation in the wild is now confirmed.