Cybertech Europe 2026-IT Industry Official Media Partner

Critical Gitea vulnerability is being actively exploited

IT industry IT industry

Looking for a Shorter Overview?

Key Moments

Vulnerability in the diffpatch function

A malicious Git hook can be installed via diffpatch and run with Gitea's permissions.

Open registration lowers the threshold

External users can create accounts and repositories to exploit the vulnerability if open registration is enabled.

Correction in version 1.27.1

The vulnerability is fixed in Gitea 1.27.1 and older versions should be upgraded quickly.

Recommended safety measures

Follow updates with checking accounts, hooks and logs as well as isolation in case of suspected intrusion.

CISA warns of active exploitation of CVE-2026-60004 in the self-hosted development platform Gitea. The vulnerability could allow attackers to execute commands on the server and has been fixed in version 1.27.1.

Organizations that run their own Gitea installations are urged to urgently check the software version and configuration.

The vulnerability could allow attackers to execute commands on the server and has been fixed in version 1.27.1

The US Cybersecurity Agency CISA has added CVE-2026-60004 to its catalog of actively exploited vulnerabilities, Known Exploited Vulnerabilities. This means that the authority assesses that there is reliable evidence of actual exploitation. CISA's KEV entry for CVE-2026-60004

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

Malicious Git hook can be executed on the server

The vulnerability is in Gitea's diffpatch-function. Through a specially designed patch, a user with write access to a repository can install an executable Git hook.

When the hook is activated, the attacker can run arbitrary commands with the same operating system privileges as the Gitea service.

Depending on how the installation is isolated, a successful attack could provide access to:

  • Gitea's configuration file and application secrets.
  • Database information and database content.
  • Mounted code repositories.
  • OAuth and integration credentials.
  • Secrets in the process's environmental variables.
  • Other internal systems that the server can reach.

The vulnerability has been given a severity rating of critical and a CVSS score of 9.8. Gitea's official security advice

Open registration can lower the threshold

The attack normally requires an account with the ability to write to a repository.

However, on installations where open self-registration is enabled, an external visitor can create a regular account, establish a new repository, and thus gain the required access.

This means that the attack can in practice be carried out without a pre-existing user account on installations using this configuration.

For the exploit to work, Git 2.32 or later is also required, an enabled diffpatch-route and a temporary file space that is both writable and executable.

Version 1.27.1 contains the fix

The Security Council states that Gitea versions starting from 1.17 but older than 1.27.1 are affected. The fix is included in Gitea 1.27.1, which was released on July 27, 2026.

Gitea recommends all users to upgrade as soon as possible. Gitea's information about version 1.27.1

Updating should be combined with incident control

Since the vulnerability is now considered to be actively exploited, an upgrade should not be the only measure.

Organizations should also:

  • Check all internet-connected Gitea installations and their versions.
  • Upgrade to 1.27.1 or a later available version.
  • Limit or close open user registration if the feature is not needed.
  • Review recently created accounts and repositories.
  • Investigate unexpected Git hooks and changes in temporary directories.
  • Review Gitea, system, and network logs for unusual command execution.
  • Rotate application, database, OAuth, and integration credentials if a breach is suspected.
  • Isolate the server and conduct a full incident analysis in case of confirmed anomalies.

Gitea is often used as a self-hosted alternative to cloud-based development platforms. A breach can therefore affect source code, credentials, automated build flows, and connected production environments.

Related Posts

New study: The average web application has 20 security flaws

The average web application contains 20 security vulnerabilities, according to new research from Barracuda. Many of the vulnerabilities are due to incorrect security settings and oversights that could have been avoided.

Cyberattacks against Swedish businesses are increasing most in the Nordic countries

Swedish businesses were exposed to an average of 2,352 cyberattacks per week in July. This is 36 percent more than the previous year and the sharpest increase…

Check Point Software Stops Massive Phishing Campaign Targeting 9,000 Organizations

Check Point Software has identified and stopped a massive phishing campaign involving approximately 24,700 emails targeting more than 9,000 organizations. The attackers used fake…

Questions Answered

What is CVE-2026-60004 in Gitea?

A critical vulnerability that could lead to command execution on the server.

How can attackers exploit the vulnerability?

By installing a malicious Git hook via the diffpatch function.

Which versions of Gitea are affected?

Versions from 1.17 up to but excluding 1.27.1 are vulnerable.

What actions are recommended after detection?

Upgrade, check accounts, hooks, logs and isolate if an intrusion is suspected.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT