CISA Warns of Active Exploitation of Critical Gitea Remote Code Execution Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of CVE-2026-60004, a critical remote code execution (RCE) vulnerability in Gitea. This flaw allows an attacker with repository write access to execute arbitrary shell commands, with reports indicating the deployment of cryptocurrency-miner-like payloads. The vulnerability affects Gitea versions from 1.17 and was patched in 1.27.1.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.