๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-60004: Gitea Code Injection Vulnerability
infovulnerability๐ฅ Actively Exploited
security
Summary
Gitea (a Git repository management system) has a code injection vulnerability where someone with write access to a repository can send a malicious patch to trick the system into running shell commands as the Gitea service account. This vulnerability is currently being exploited by attackers in real-world attacks.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Patch Available
Yes
Exploit Maturity
๐ฅ Actively Exploited
Disclosure Date
August 24, 2026
Classification
Attack SophisticationModerate
Monthly digest โ independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-60004
First tracked: August 25, 2026 at 02:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%