www.securityweek.com 8/26/2026, 5:50:44 AM · external

CISA Warns of Exploited Gitea Flaw CVE-2026-60004 Patch by Aug 28

CISA Warns of Exploited Gitea Flaw CVE-2026-60004 Patch by Aug 28
Developing story vulnerability 7 articles tracked
Gitea Code Injection Flaw (CVE-2026-60004) exploited in the wild
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CISA has issued a warning about a recently exploited vulnerability in Gitea, an open source software development platform, tracked as CVE-2026-60004, which allows remote code execution via a code injection flaw. Despite being patched in version 1.27.1, it’s been actively targeted, and organizations are required to address it by August 28. The flaw enables attackers with repository write access to run malicious commands.

This is not the first such vulnerability, as another related flaw, CVE-2026-20896, was also identified recently. CISA has yet to list this earlier vulnerability in its Known Exploited Vulnerabilities catalog.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline