Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-26 ยท updated: 2026-08-26 ยท tags: [incident, gov-agency, kev, cve, supply-chain, sector-technology, sector-government] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government] ยท au_impact: true

CISA Adds Actively Exploited Gitea Code-Injection Flaw (CVE-2026-60004) to KEV Catalog

On 25 August 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-60004, a critical code-injection vulnerability affecting the Gitea self-hosted Git platform, to its Known Exploited Vulnerabilities (KEV) Catalog.

Overview

Attribute Detail
Catalog Addition CVE-2026-60004 (Gitea Code Injection)
Publishing Agency Cybersecurity and Infrastructure Security Agency (CISA)
Date Added 2026-08-25
Mandate Binding Operational Directive (BOD) 26-04
Scope US Federal Civilian Executive Branch (FCEB) agencies and global software engineering pipelines

Impact & Context

The inclusion of CVE-2026-60004 follows recent KEV additions targeting enterprise infrastructure components, including Oracle HTTP Server (CVE-2026-21962) and Zimbra Collaboration Suite (CVE-2026-73570).

Gitea is widely utilized by engineering teams as a lightweight, self-hosted version control system. Active exploitation of self-hosted source code management tools creates direct software supply chain risk, enabling threat actors to inject malicious backdoors, exfiltrate proprietary IP, or manipulate CI/CD release artifacts.

Remediation Requirements

  • FCEB Agencies: Must apply vendor security patches within established BOD 26-04 remediation windows.
  • Enterprise Engineering Teams: Conduct retroactive log reviews for unusual Git command invocations, audit CI/CD runner access, and ensure internet-exposed Gitea webhooks and portals are restricted.

Australian Context

Australian enterprises and defense supply chain contractors operating self-hosted Git repositories should treat this alert with high priority in accordance with ASD ACSC guidance on software supply chain security and rapid vulnerability mitigation.

Sources