CISA has issued a warning about a recently exploited vulnerability in Gitea, an open source software development platform, tracked as CVE-2026-60004, which allows remote code execution via a code injection flaw. Despite being patched in version 1.27.1, it’s been actively targeted, and organizations are required to address it by August 28. The flaw enables attackers with repository write access to run malicious commands.
This is not the first such vulnerability, as another related flaw, CVE-2026-20896, was also identified recently. CISA has yet to list this earlier vulnerability in its Known Exploited Vulnerabilities catalog.