news.mlab.sh
Back to the feed
vulnerability

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical
Image: The Hacker News
Summary

A critical remote code execution vulnerability (CVE-2026-60004) in Gitea is actively being exploited to deploy cryptocurrency miners. The vulnerability, stemming from default open registration, allows attackers to gain repository write access and execute malicious Git hooks. A hosting provider reported a significant CPU spike on one of their servers, leading to an investigation that revealed the exploitation of this vulnerability. CISA has added the flaw to its KEV catalog, and federal agencies are required to patch the vulnerability by August 28, 2026.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.