CVE-2026-60004
CVE-2026-60004 is a code-injection vulnerability in the Gitea self-hosted Git service that allows attackers to execute arbitrary code on vulnerable servers. On 25 August 2026, CISA added CVE-2026-60004 to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-60004 |
| Product | Gitea (Self-hosted Git service) |
| Type | Code injection |
| KEV Status | Added to CISA KEV on 2026-08-25 (BOD 26-04) |
| Exploitation Status | Actively exploited in the wild |
Context & Impact
Gitea is widely deployed across small development teams, internal DevOps toolchains, and enterprise self-hosted environments. The inclusion in CISA's KEV Catalog requires US Federal Civilian Executive Branch (FCEB) agencies to remediate within established BOD 26-04 deadlines and assess systems for potential pre-patch compromise. The vulnerability presents significant supply chain and code integrity risks for any engineering organisation operating self-hosted Gitea instances.
Remediation
Organisations running self-hosted Gitea instances should: 1. Update Gitea installations immediately to the latest patched release. 2. Review server logs and Git repository commit histories for signs of unauthorised access or pre-patch exploitation. 3. Restrict administrative interfaces and repository management endpoints behind zero-trust access controls or corporate VPNs.
Australian Context
Development teams and government entities across Australia leveraging open-source and self-hosted version control infrastructure like Gitea should review their exposure and ensure patching compliance aligns with ACSC Essential Eight mitigation strategies regarding application control and rapid patching.
Sources
- CISA โ CISA Adds One Known Exploited Vulnerability to Catalog (Archived: web.archive.org save submitted 26 August 2026)