Critical Gitea RCE Vulnerability Under Attack
Open registration on developer platforms generally streamlines onboarding processes. However, concerning Gitea, this convenience inadvertently transformed a critical vulnerability into an easily accessible intrusion point. The Shadowserver Foundation recently identified a staggering 8,393 internet-facing Gitea servers. As of August 27th, these systems remained entirely vulnerable to CVE-2026-60004, a severe flaw carrying a 9.8 CVSS 3.1 rating. Consequently, these exposed servers currently face relentless Remote Code Execution (RCE) attacks.
The Mechanism of Exploitation
This critical error empowers any user possessing repository write permissions to inflict severe damage. The attacker transmits specifically crafted, malicious data directly through the diffpatch API. Consequently, they can execute arbitrary commands utilizing the elevated privileges of the Gitea system account. This highly vulnerable mechanism permits an attacker to covertly install and trigger a malicious Git hook. Essentially, this is a background utility script designed to execute automatically during specific repository interactions.
The Danger of Default Settings
Technically, successful exploitation strictly requires write access. However, Gitea enables autonomous user registration by default. Therefore, a malicious actor lacking any prior credentials can effortlessly create a new account. They can subsequently establish a personal repository, instantly acquiring the necessary permissions to trigger the vulnerability. This devastating scenario drastically lowers the attack threshold against servers operating with standard, default configurations.
Patching Delays and Ongoing Risk
Gitea definitively resolved CVE-2026-60004 with the release of version 1.27.1 on July 27th. The developers urgently implored administrators to update their vulnerable servers immediately. Despite the ready availability of this crucial patch, thousands of systems remained dangerously unprotected an entire month later. Shadowserver persistently scans the internet, diligently notifying responsible owners whenever they detect exposed, vulnerable Gitea instances.
Government Directives and Known Exploitation
Highlighting the severe threat, the United States Cybersecurity and Infrastructure Security Agency (CISA) officially appended CVE-2026-60004 to its catalog of actively exploited vulnerabilities on August 25th. They explicitly commanded all federal civilian agencies to deploy the necessary patch by August 28th. While the agency has not publicly detailed the specific attack methodologies, earlier reports indicated malicious actors were actively installing cryptocurrency miners upon unprotected Gitea servers.
Essential Mitigation Strategies
Security experts strongly advise all Gitea administrators to upgrade their servers to version 1.27.1 or newer without delay. This vital update decisively eliminates the possibility of command injection via the diffpatch API. Ultimately, it securely closes the exact pathway currently exploited in these ongoing real-world attacks. This urgent verification process is especially critical for any internet-accessible installations where the default, autonomous user registration feature remains active.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.