Critical Gitea Remote Code Execution Vulnerability Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation of a critical remote code execution (RCE) vulnerability, CVE-2026-60004, impacting Gitea. The flaw allows an attacker with ordinary repository write access to execute arbitrary shell commands, and with default open registration, an unauthenticated visitor can exploit the issue by creating an account and repository.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai