Ethical Hacking News
The U.S. CISA has added a critical Gitea flaw to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the importance of timely patching and vulnerability management. This critical remote code execution flaw, rated with a CVSS score of 9.8, poses a significant threat to Gitea users, particularly those who utilize the self-hosted platform for hosting and managing Git repositories. Cybersecurity professionals and organizations are advised to review the catalog and address the vulnerabilities in their infrastructure to protect against attacks exploiting the flaws in the catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Gitea flaw (CVE-2026-60004) to the Known Exploited Vulnerabilities (KEV) catalog. The flaw is a critical remote code execution vulnerability rated with a CVSS score of 9.8. The vulnerability affects Gitea versions from 1.17 and was fixed in 1.27.1. The flaw can be exploited by an unauthenticated attacker to execute arbitrary shell commands as the Gitea service user. The CISA has ordered federal agencies to fix the flaw by August 28, 2026, to protect their networks. Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw (CVE-2026-60004) has also been added to the KEV catalog. The flaw is critical and affects Oracle HTTP Server and Oracle Weblogic Server versions from 10.7.0.2. The CISA has ordered federal agencies to fix the flaw by September 4, 2026, to protect their networks.
The recent addition of Gitea flaw (CVE-2026-60004) to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) serves as a stark reminder of the importance of proactive cybersecurity measures. This critical remote code execution flaw, rated with a CVSS score of 9.8, poses a significant threat to Gitea users, particularly those who utilize the self-hosted platform for hosting and managing Git repositories. Gitea, an open-source alternative to GitHub or GitLab, enables open registration by default, making it vulnerable to exploitation by unauthenticated attackers.
The vulnerability, tracked as CVE-2026-60004, affects Gitea versions from 1.17 and was fixed in 1.27.1. The diffpatch API can be abused to plant and execute a malicious Git hook, allowing an attacker with write access to a repository to execute arbitrary shell commands as the Gitea service user. This flaw can be exploited by an unauthenticated attacker, who can create an account, create a repository, and deploy a malicious payload without existing credentials.
The recent incident highlights the importance of timely patching and vulnerability management. The reported attack used the vulnerability to deploy a cryptocurrency-miner-like payload after an exposed Gitea instance allowed open registration and anonymous access to its web interface. As a result, the U.S. CISA has ordered federal agencies to fix the flaw by August 28, 2026, to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend that private organizations review the catalog and address the vulnerabilities in their infrastructure. This is especially crucial for organizations that utilize Gitea for their Git repository needs. The recent incident emphasizes the importance of regular security updates, careful configuration, and robust vulnerability management.
In addition to Gitea, the CISA has added another Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw (CVE-2026-60004) to the KEV catalog. This critical flaw, rated with a CVSS score of 9.8, poses a significant threat to Oracle users. The vulnerability affects Oracle HTTP Server and Oracle Weblogic Server versions from 10.7.0.2 and was fixed in 10.8.0.1. The CISA has ordered federal agencies to fix the flaw by September 4, 2026, to protect their networks against attacks exploiting the flaws in the catalog.
The recent additions to the KEV catalog highlight the ever-evolving threat landscape and the importance of staying vigilant in the face of emerging vulnerabilities. As cybersecurity professionals and organizations, it is crucial to prioritize proactive vulnerability management, timely patching, and robust security measures to safeguard against such threats.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Critical-Gitea-Flaw-A-Wake-Up-Call-for-Cybersecurity-Professionals-and-Organizations-ehn.shtml
https://securityaffairs.com/197854/security/u-s-cisa-adds-gitea-flaw-to-its-known-exploited-vulnerabilities-catalog.html
https://nvd.nist.gov/vuln/detail/CVE-2026-60004
https://www.cvedetails.com/cve/CVE-2026-60004/
https://nvd.nist.gov/vuln/detail/CVE-2026-60004
https://www.cvedetails.com/cve/CVE-2026-60004/
Published: Wed Aug 26 05:08:35 2026 by llama3.2 3B Q4_K_M