More than 8,300 internet-exposed Gitea instances remain unpatched against a critical code injection vulnerability that is being exploited in ongoing remote code execution attacks, according to cybersecurity monitoring group Shadowserver.
Tracked as CVE-2026-60004, the vulnerability affects Gitea’s diffpatch API endpoint. The flaw was reported by Salesforce security researcher Shai Rod and allows an authenticated attacker to submit a malicious patch that executes arbitrary shell commands with the privileges of the Gitea service account.
Although exploitation requires write access to a repository hosted on the vulnerable server, Gitea enables self-registration by default. As a result, an unauthenticated attacker may be able to create an account, establish a new repository, and exploit the vulnerability without previously stolen credentials.
“Gitea’s diffpatch endpoint can be exploited to install and execute Git hooks from content controlled in a repository. An attacker with normal write access to the repository can execute arbitrary shell commands as the Gitea OS user,” Gitea’s security team explained. “Default open registration allows unauthenticated visitors to register an account and create a repository to obtain the write access they need.”
Gitea addressed CVE-2026-60004 in version 1.27.1, released on July 27. The project urged administrators to upgrade their Gitea servers as soon as possible.
On Friday, Shadowserver warned that thousands of vulnerable Gitea servers remain publicly accessible. Its latest scan identified approximately 8,400 vulnerable Gitea servers exposed to the internet.
“Scanning/reporting Gitea instances vulnerable to CVE-2026-60004 (Code Injection) and found 8393 IPs vulnerable as of August 27, 2026,” Shadowserver said.

On Tuesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog. CISA also directed U.S. federal civilian executive branch agencies to patch affected servers within three days, by August 28, under Binding Operational Directive 26-04.
While CISA has not disclosed technical details about the attacks exploiting this vulnerability, the decision to add the flaw to its catalog may be linked to reports that threat actors are using vulnerable Gitea servers to deploy cryptocurrency-mining malware.
“These types of vulnerabilities are a frequent attack vector for malicious cyber attackers and pose significant risks to federal enterprises,” CISA warned.
In July, threat actors were also observed exploiting another critical Gitea vulnerability, CVE-2026-20896. The authentication bypass flaw affects the official Gitea Docker image when reverse-proxy authentication headers are enabled.
Gitea is a self-hosted alternative to cloud-based code hosting and DevOps platforms such as GitHub, GitLab, and Bitbucket. The project has more than 400,000 installations and nearly 1,500 contributors.
The overall prevention score can hide what happens after initial access. If an attacker uses valid credentials, your defenses can weaken significantly.
Blue Report 2026 measures defensive techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




