CISA Adds Gitea Code Injection to KEV List
CISA added actively exploited Gitea code injection flaw CVE-2026-60004 to its Known Exploited Vulnerabilities catalog, requiring federal remediation.
CISA has added CVE-2026-60004, a code injection vulnerability in Gitea, to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation in the wild. The advisory does not detail the exploitation vector, threat actors involved, or specific victims, but flags the vulnerability as a current attack vector being leveraged by malicious cyber actors.
Per Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies must prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those enabling full post-exploitation control, and are required to check for prior compromise before patching. While the directive is binding only on FCEB agencies, CISA recommends all organizations running Gitea instances review their exposure and apply available patches or mitigations promptly given the confirmed active exploitation.
Defenders should identify any internet-facing Gitea deployments, confirm patch status against CVE-2026-60004, and review logs for signs of code injection attempts or unauthorized changes predating remediation.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free