Act
active
Critical Gitea RCE (CVE-2026-60004) Actively Exploited, CISA KEV Listed
- Engineer — Act: CISA KEV-listed RCE (CVSS 9.8) with public PoC requires only repository write access to execute arbitrary shell commands — patch Gitea immediately and audit server process trees and outbound connections for miner-related IOCs.
- SOC/IR — Act: Active exploitation with miner-like payload delivery gives a clear detection angle — hunt for anomalous child processes spawned by the Gitea process, unusual outbound connections from CI/Git infrastructure, and unexpected CPU spikes on self-hosted Git servers since the CVE was published.
- Leader — Plan: If your organization runs self-hosted Gitea, confirm with engineering teams this week whether the patch has been applied; a compromised source code host is a supply-chain risk that may warrant customer notification depending on your disclosure obligations.
- Signals: CVE-2026-60004 — CISA KEV: listed, EPSS n/a, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.