Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-30 ยท updated: 2026-08-30 ยท tags: [incident, gitea, cve-2026-60004, kev, code-injection, actively-exploited, devops] ยท confidence: high ยท severity: critical ยท affected_sectors: [Global (Macro)] ยท au_impact: false

Over 8,300 Gitea Servers Remain Vulnerable to Code-Execution Attacks as Flaw Lands on CISA KEV

Shadowserver reports that 8,393 internet-exposed Gitea instances were still vulnerable to CVE-2026-60004 as of 27 August 2026 โ€” more than 8,300 unpatched servers. The code-injection flaw lets an attacker execute arbitrary shell commands as the Gitea service account by submitting malicious patches via the diffpatch API endpoint, and because Gitea ships with self-registration enabled by default, an unauthenticated attacker can register an account, create a repository and trigger the flaw without prior credentials.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 25 August 2026, confirming active exploitation. Gitea fixed the issue in version 1.27.1, released 27 July, and Shadowserver continues scanning and reporting vulnerable instances. The exposure sits in the same remediation wave as the ACSC's active-exploitation alert for TeamCity On-Premises in Australia: internet-exposed CI/CD and code-hosting platforms are under active attack and should not be treated as a passive risk.

Source