Gitea CVE-2026-60004: Critical RCE Exploited for Cryptomining

A CVSS 9.8 code-injection flaw lets low-privilege users abuse Gitea's diffpatch API to plant Git hooks and run shell commands. CISA added CVE-2026-60004 to KEV after in-the-wild cryptomining; over 8,300 servers remain exposed.

2026-08-31T22:43:52.750Z
Rudra Verma, Senior Security Architect & Researcher