CISA Adds Actively Exploited Gitea Code-Injection Flaw (CVE-2026-60004) to KEV Catalog
On 25 August 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-60004, a critical code-injection vulnerability affecting the Gitea self-hosted Git platform, to its Known Exploited Vulnerabilities (KEV) Catalog.
Overview
| Attribute | Detail |
|---|---|
| Catalog Addition | CVE-2026-60004 (Gitea Code Injection) |
| Publishing Agency | Cybersecurity and Infrastructure Security Agency (CISA) |
| Date Added | 2026-08-25 |
| Mandate | Binding Operational Directive (BOD) 26-04 |
| Scope | US Federal Civilian Executive Branch (FCEB) agencies and global software engineering pipelines |
Impact & Context
The inclusion of CVE-2026-60004 follows recent KEV additions targeting enterprise infrastructure components, including Oracle HTTP Server (CVE-2026-21962) and Zimbra Collaboration Suite (CVE-2026-73570).
Gitea is widely utilized by engineering teams as a lightweight, self-hosted version control system. Active exploitation of self-hosted source code management tools creates direct software supply chain risk, enabling threat actors to inject malicious backdoors, exfiltrate proprietary IP, or manipulate CI/CD release artifacts.
Remediation Requirements
- FCEB Agencies: Must apply vendor security patches within established BOD 26-04 remediation windows.
- Enterprise Engineering Teams: Conduct retroactive log reviews for unusual Git command invocations, audit CI/CD runner access, and ensure internet-exposed Gitea webhooks and portals are restricted.
Australian Context
Australian enterprises and defense supply chain contractors operating self-hosted Git repositories should treat this alert with high priority in accordance with ASD ACSC guidance on software supply chain security and rapid vulnerability mitigation.
Sources
- CISA โ CISA Adds One Known Exploited Vulnerability to Catalog (Archived: web.archive.org save submitted 26 August 2026)