CISA: Hackers Are Actively Exploiting a Patched Gitea Flaw That Lets Them Run Malicious Commands
A security hole in Gitea, a widely used code-hosting platform, is being exploited in the wild. A patch has existed since late July, but federal agencies have until August 28 to apply it.

Key points
- CVE-2026-60004, a remote code execution flaw in Gitea, is being actively exploited, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed.
- Gitea released a fix in version 1.27.1 in late July 2026; unpatched installations remain at risk.
- CISA ordered all U.S. Federal agencies to apply the patch by August 28, 2026.
- A second Gitea vulnerability, CVE-2026-20896, was flagged as exploited in early July and has not yet been added to CISA's official warning list.
- Who is behind the attacks and what they're after remains unknown.
Gitea lets companies run their own private code-hosting service, similar to GitHub but installed on their own servers. Development teams use it to store source code, automate software builds, and manage access to the software they ship to customers. Break in, and you may reach that software.
What does this vulnerability actually do?
The flaw lets an attacker with write access to at least one repository plant a hidden instruction file and use it to run arbitrary commands on the server. CISA's description is blunt: an attacker sends a malicious change request to Gitea's internal file-comparison tool, slips in an executable script called a Git hook (a small program that runs automatically when certain actions occur in a repository), then executes commands as the Gitea service account, meaning with the same system permissions the Gitea software itself holds.
If a criminal or rogue insider has even limited access to one project on your Gitea instance, this bug can let them take over the whole server.
The flaw is tracked as CVE-2026-60004 and was fixed in Gitea version 1.27.1, released in late July.
Should organisations running Gitea be worried?
Yes, if they haven't yet updated. No public reporting had flagged attacks before CISA's warning, which suggests whoever is running the campaign isn't broadcasting their methods.
The attackers' identity and motive are unknown. That could mean targeted espionage against specific software supply chains, or opportunistic scanning for any exposed instance. Either way, an unpatched server is a live risk.
A second vulnerability, CVE-2026-20896, was reported as exploited in early July. We first covered it on 6 July 2026. CISA hasn't added it to its formal catalogue, but its existence means Gitea has faced back-to-back exploitation within weeks.
| Detail | CVE-2026-60004 | CVE-2026-20896 |
|---|---|---|
| Reported exploited | August 2026 | July 2026 |
| CISA KEV listed | Yes | No |
| Fixed in version | 1.27.1 | Not confirmed |
| Federal patch deadline | August 28, 2026 | None set |
What should your organisation do right now?
Update Gitea to version 1.27.1 or later immediately. Check access logs for unusual activity, particularly automated actions not triggered by known users. Audit who holds write access and remove accounts that no longer need it.
If your Gitea instance is exposed to the public internet, place it behind a private network or a VPN (a virtual private network, which restricts who can reach the server) while you investigate. This is the third active-exploitation warning from CISA we've reported in August alone, following alerts on Microsoft, VMware and Apple products on 18 August and a second batch two days later. The agency's pace isn't slowing.



