8,300 unpatched Gitea instances exploited for remote code execution via CVE-2026-60004; CISA mandates US federal agencies patch the flaw within three days; attackers are actively deploying cryptocurrency mining malware on vulnerable servers.
| IOC Type | Value | Description | Relevant MITRE ATT&CK Techniques |
|---|---|---|---|
| Domain |
shadowserver.org
|
Cybersecurity watchdog group that scanned and reported 8,393 vulnerable Gitea IPs. | T1190 |
| Domain |
cisa.gov
|
U.S. Cybersecurity and Infrastructure Security Agency that added the flaw to its catalog of actively exploited flaws and ordered FCEB agencies to patch. | T1190 |
| Vulnerability | CVE-2026-60004 | Critical RCE vulnerability in Gitea versions 1.17–1.27.0 | T1190 |
| Vulnerability | CVE-2026-20896 | Authentication bypass vulnerability in official Gitea Docker image allowing impersonation via X-WEBAUTH-USER header when REVERSE_PROXY_TRUSTED_PROXIES=* | T1190 |
| Code | Title |
|---|---|
| T1190 | Exploit Public-Facing Application |
| T1059.004 | Command and Scripting Interpreter: Unix Shell |
| T1078 | Valid Accounts |
| T1496 | Resource Hijacking |
| T1068 | Exploitation for Privilege Escalation |
| Type | Value |
|---|---|
| Sector | Federal Government |
| Sector | Information Technology |
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. The code injection vulnerability (
Federal Civilian Executive Branch (FCEB) agencies to patch their servers within three days, by August 28, as mandated by Binding Operational Directive (BOD) 26-04 . While the cybersecurity agency has yet to share further details on attacks targeting this flaw, the move was likely prompted by reports of in-the-wild exploitation, in which the attackers are deploying cryptocurrency mining malware on unpatched Gitea servers. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," CISA warned . In July, threat actors were also spotted abusing another critical vulnerability (