www.cisa.gov 8/26/2026, 2:26:18 PM · external

CISA's KEV Catalog Adds Gitea Flaw, Urges Prompt Patching

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

THE Known Exploited Vulnerabilities (KEV) Catalog is maintained by the Cybersecurity & Infrastructure Security Agency (CISA) to help organizations manage vulnerabilities that have been exploited in real-world scenarios. It serves as a crucial resource for vulnerability management prioritization. Users can report new vulnerabilities not listed in the catalog.

The catalog includes detailed entries such as the Gitea Code Injection Vulnerability (CVE-2026-60004), which allows repository access to execute harmful commands. Organizations are guided to follow specific mitigation steps, including compliance with CISA directives. The catalog is available in multiple formats including CSV and JSON.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline