Skip to main content
Cyber News & CTI Reports :: 2026-08-28 | Over 8,300 Gitea servers vulnerable to code execution attacks
Contact Page | Privacy Policy

2026-08-28 | Over 8,300 Gitea servers vulnerable to code execution attacks

1. AI Summary

8,300 unpatched Gitea instances exploited for remote code execution via CVE-2026-60004; CISA mandates US federal agencies patch the flaw within three days; attackers are actively deploying cryptocurrency mining malware on vulnerable servers.

2. IOCs

IOC Type Value Description Relevant MITRE ATT&CK Techniques
Domain
shadowserver.org
Cybersecurity watchdog group that scanned and reported 8,393 vulnerable Gitea IPs. T1190
Domain
cisa.gov
U.S. Cybersecurity and Infrastructure Security Agency that added the flaw to its catalog of actively exploited flaws and ordered FCEB agencies to patch. T1190
Vulnerability CVE-2026-60004 Critical RCE vulnerability in Gitea versions 1.17–1.27.0 T1190
Vulnerability CVE-2026-20896 Authentication bypass vulnerability in official Gitea Docker image allowing impersonation via X-WEBAUTH-USER header when REVERSE_PROXY_TRUSTED_PROXIES=* T1190

3. MITRE ATT&CK

Code Title
T1190 Exploit Public-Facing Application
T1059.004 Command and Scripting Interpreter: Unix Shell
T1078 Valid Accounts
T1496 Resource Hijacking
T1068 Exploitation for Privilege Escalation

4. Targets

Type Value
Sector Federal Government
Sector Information Technology

5. Article Details

6. Original text

Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. The code injection vulnerability (

CVE-2026-60004
) targeted in these attacks was reported by Salesforce security researcher Shai Rod , and it allows authenticated attackers to execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches via the diffpatch API endpoint. While successful exploitation requires repository write access to repositories hosted on vulnerable servers, Gitea comes with self-registration enabled by default, allowing unauthenticated attackers to register an account, create a new repository, and trigger the vulnerability without prior credentials. "Gitea's diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content. An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user," Gitea's security team explains . "With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository." Gitea released version 1.27.1 on July 27 to address
CVE-2026-60004
and advised users to upgrade their servers as soon as possible. On Friday, Internet security watchdog group Shadowserver warned that nearly 8,400 Gitea servers exposed online are still unsecured and remain vulnerable to ongoing attacks. "We are scanning/reporting Gitea instances vulnerable to
CVE-2026-60004
(code injection), with 8393 IPs found vulnerable on 2026-08-27," Shadowserver said . Vulnerable Gitea instances (Shadowserver) ​On Tuesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added the vulnerability to its catalog of actively exploited flaws and ordered U.S.

Federal Civilian Executive Branch (FCEB) agencies to patch their servers within three days, by August 28, as mandated by Binding Operational Directive (BOD) 26-04 . While the cybersecurity agency has yet to share further details on attacks targeting this flaw, the move was likely prompted by reports of in-the-wild exploitation, in which the attackers are deploying cryptocurrency mining malware on unpatched Gitea servers. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," CISA warned . In July, threat actors were also spotted abusing another critical vulnerability (

CVE-2026-20896
) in the official Gitea Docker image, an authentication bypass flaw affecting Gitea instances with reverse proxy authentication headers enabled. Gitea is a self-hosted alternative to cloud-hosted GitHub, GitLab, and Bitbucket code hosting and DevOps platforms, with more than 400,000 installations and nearly 1,500 contributors. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report