CyberNotableSingle-sourceDeveloping
5.5
CISA confirms active exploitation of Gitea remote code execution vulnerability CVE-2026-60004
SecurityWeek·US·about 14 hours ago
Threat actors are actively exploiting a critical-severity vulnerability in self-hosted Gitea instances to perform unauthorized code injection. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, signaling an urgent need for patching to prevent potential remote code execution.