Skip to main content
Back to Newswire
Security

More than 8,300 exposed Gitea servers remain vulnerable to active attacks

More than 8,300 exposed Gitea servers remain vulnerable to active attacks Image: Primary
Shadowserver found 8,393 internet-exposed Gitea servers vulnerable on August 27 to CVE-2026-60004, a critical code-injection flaw being exploited in remote-code-execution attacks. Gitea released version 1.27.1 on July 27 to fix the issue. Attackers with repository write access can execute commands as the Gitea service account; default self-registration can let an unauthenticated visitor obtain that access. CISA has added the flaw to its actively exploited catalog and ordered federal civilian agencies to patch by August 28.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire