Threat Intelligence

Critical Gitea Flaw Under Active Attack — Patch Now Before It Drops Malware

The Hacker News · 26 Aug 2026
Key Takeaway If your business runs a self-hosted Gitea server, patch immediately and review recent repository activity for signs of compromise.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about active exploitation of a critical vulnerability in Gitea, a popular self-hosted code repository platform used by developers and small businesses to manage software projects. The flaw, tracked as CVE-2026-60004, carries a severe CVSS score of 9.8 and allows an attacker with only basic write access to a repository to execute arbitrary shell commands on the underlying server.

This is a serious issue because it lowers the bar for attackers significantly — rather than needing deep system access, a threat actor only needs limited repository permissions to potentially take full control of a server. Reports indicate that attackers are already exploiting this flaw in the wild, with some attacks reportedly dropping malware resembling cryptocurrency mining payloads onto compromised systems.

Any Australian business running a self-hosted Gitea instance — often used by software development teams, IT departments, or technical contractors — should treat this as an urgent priority. Unpatched systems could be silently compromised, leading to resource theft, further malware deployment, or use as a launchpad for additional attacks within your network.

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.