More than 8,300 Internet-exposed Gitea servers remain vulnerable to a critical code injection flaw that attackers are actively exploiting.

Gitea code execution flaw affects exposed servers

The vulnerability, tracked as CVE-2026-60004, allows attackers with repository write access to execute commands with the permissions of the Gitea service account.

The issue affects Gitea’s diffpatch API endpoint. Attackers can abuse it to run malicious code through repository-controlled content.

Although the flaw requires repository write access, Gitea enables self-registration by default. As a result, an unauthenticated visitor may be able to register an account, create a repository and gain the access needed to exploit a vulnerable server.

Thousands of servers remain unpatched

Gitea released version 1.27.1 on July 27 to fix the vulnerability. However, Shadowserver reported that 8,393 Internet-exposed instances remained vulnerable on August 27.

The high number of exposed servers creates a substantial attack surface. Administrators should review all public-facing Gitea instances and apply the available security update without delay.

Gitea is a self-hosted platform for source-code hosting and DevOps work. It serves as an alternative to cloud services such as GitHub, GitLab and Bitbucket.

CISA adds flaw to exploited vulnerabilities list

The US Cybersecurity and Infrastructure Security Agency added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog.

CISA ordered Federal Civilian Executive Branch agencies to patch affected servers by August 28. The agency said this kind of vulnerability can pose a serious risk to federal networks.

Reports indicate that attackers have used the Gitea code execution flaw to deploy cryptocurrency-mining malware on unpatched servers. CISA has not released further technical details about the attacks.

Gitea users should update immediately

Administrators should update to Gitea version 1.27.1 or later. They should also restrict repository access, review account-registration settings and look for suspicious activity on their servers.

In July, attackers also exploited CVE-2026-20896, another critical Gitea vulnerability. That flaw affected Docker deployments using reverse-proxy authentication headers.

The Gitea code execution flaw shows why teams should patch self-hosted development platforms quickly. These systems can hold source code, credentials and deployment secrets that attackers may target.


0 responses to “More Than 8,300 Gitea Servers Remain Exposed to Code Execution Attacks”