Cyber Resilience
← All news
Confirmed

KEV: CVE-2026-60004 — Gitea Gitea (Gitea Code Injection Vulnerability)

Our takeCISA added CVE-2026-60004 to its KEV catalog: this code injection flaw in Gitea lets anyone with repo write access plant a malicious Git hook and run commands as the service account. It is confirmed exploited in the wild. Update to 1.27.1 or later if you self-host Gitea.
Sources (3)
What this means for you — Security leader:CISA added CVE-2026-60004 (Gitea code injection) to its KEV catalog: exploitation is confirmed. Enterprises and MSPs running self-hosted Gitea should update to 1.27.1 or later immediately.
What this means for you — Lean IT orgs:If you self-host Gitea, update it to version 1.27.1 or newer right away. Most smaller teams that only use hosted Git services can ignore this one.
What this means for you — MSP:Confirm whether any clients run self-hosted Gitea; if they do, update them to 1.27.1 or later immediately. This KEV addition makes it a priority under BOD 22-01 / 26-04.
What this means for you — Researcher:CISA added CVE-2026-60004 to the KEV catalog after confirming in-the-wild exploitation. The flaw lets repository write access lead to Git hook injection and command execution as the Gitea service account.