# More than 8,300 exposed Gitea servers remain vulnerable to active attacks

_Wednesday, August 26, 2026 at 8:00 PM EDT · Security · Latest · Tier 1 — Major_

![More than 8,300 exposed Gitea servers remain vulnerable to active attacks — Primary](https://www.bleepstatic.com/content/hl-images/2026/08/28/Gitea.jpg)

Shadowserver found 8,393 internet-exposed Gitea servers vulnerable on August 27 to CVE-2026-60004, a critical code-injection flaw being exploited in remote-code-execution attacks. Gitea released version 1.27.1 on July 27 to fix the issue. Attackers with repository write access can execute commands as the Gitea service account; default self-registration can let an unauthenticated visitor obtain that access. CISA has added the flaw to its actively exploited catalog and ordered federal civilian agencies to patch by August 28.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/)

---
Canonical: https://techandbusiness.org/newswire/2Zw23_nD_W5_RWRZohhC-o
Retrieved: 2026-08-28T15:49:56.928Z
Publisher: Tech & Business (techandbusiness.org)
