Cybertech Europe 2026-IT Industry Official Media Partner

Critical Gitea vulnerability is being actively exploited

Critical Gitea vulnerability is being actively exploited | IT Industry Critical Gitea vulnerability is being actively exploited | IT Industry
Critical Gitea vulnerability is being actively exploited

Looking for a Shorter Overview?

Key Moments

Vulnerability in the diffpatch function

A manipulative patch can install executable Git hooks that issue server commands.

Risks of open enrollment

External can create account and repository to exploit the vulnerability.

Correction in version 1.27.1

The vulnerability is fixed in Gitea 1.27.1 and users should upgrade immediately.

Important measures for active use

Monitoring, upgrading, reviewing accounts and logs, and incident analysis are recommended.

CISA warns of active exploitation of CVE-2026-60004 in the self-hosted development platform Gitea. The vulnerability could allow attackers to execute commands on the server and has been fixed in version 1.27.1.

Organizations that run their own Gitea installations are urged to urgently check the software version and configuration.

The vulnerability could allow attackers to execute commands on the server and has been fixed in version 1.27.1

The US Cybersecurity Agency CISA has added CVE-2026-60004 to its catalog of actively exploited vulnerabilities, Known Exploited Vulnerabilities. This means that the authority assesses that there is reliable evidence of actual exploitation. CISA's KEV entry for CVE-2026-60004

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

Malicious Git hook can be executed on the server

The vulnerability is in Gitea's diffpatch-function. Through a specially designed patch, a user with write access to a repository can install an executable Git hook.

When the hook is activated, the attacker can run arbitrary commands with the same operating system privileges as the Gitea service.

Depending on how the installation is isolated, a successful attack could provide access to:

  • Gitea's configuration file and application secrets.
  • Database information and database content.
  • Mounted code repositories.
  • OAuth and integration credentials.
  • Secrets in the process's environmental variables.
  • Other internal systems that the server can reach.

The vulnerability has been given a severity rating of critical and a CVSS score of 9.8. Gitea's official security advice

Open registration can lower the threshold

The attack normally requires an account with the ability to write to a repository.

However, on installations where open self-registration is enabled, an external visitor can create a regular account, establish a new repository, and thus gain the required access.

This means that the attack can in practice be carried out without a pre-existing user account on installations using this configuration.

For the exploit to work, Git 2.32 or later is also required, an enabled diffpatch-route and a temporary file space that is both writable and executable.

Version 1.27.1 contains the fix

The Security Council states that Gitea versions starting from 1.17 but older than 1.27.1 are affected. The fix is included in Gitea 1.27.1, which was released on July 27, 2026.

Gitea recommends all users to upgrade as soon as possible. Gitea's information about version 1.27.1

Updating should be combined with incident control

Since the vulnerability is now considered to be actively exploited, an upgrade should not be the only measure.

Organizations should also:

  • Check all internet-connected Gitea installations and their versions.
  • Upgrade to 1.27.1 or a later available version.
  • Limit or close open user registration if the feature is not needed.
  • Review recently created accounts and repositories.
  • Investigate unexpected Git hooks and changes in temporary directories.
  • Review Gitea, system, and network logs for unusual command execution.
  • Rotate application, database, OAuth, and integration credentials if a breach is suspected.
  • Isolate the server and conduct a full incident analysis in case of confirmed anomalies.

Gitea is often used as a self-hosted alternative to cloud-based development platforms. A breach can therefore affect source code, credentials, automated build flows, and connected production environments.

Related Posts

New study: The average web application has 20 security flaws

The average web application contains 20 security vulnerabilities, according to new research from Barracuda. Many of the vulnerabilities are due to incorrect security settings and oversights that could have been avoided.

Cyberattacks against Swedish businesses are increasing most in the Nordic countries

Swedish businesses were exposed to an average of 2,352 cyberattacks per week in July. This is 36 percent more than the previous year and the sharpest increase…

Pax8: EU AI rules open a new services market for MSPs

Pax8 sees a new business opportunity for MSPs as the EU’s AI regulation comes into effect. AI governance, documentation, training and risk management can develop into recurring services for European companies.

Questions Answered

What is CVE-2026-60004 and how does it affect Gitea?

A critical vulnerability in the diffpatch function that allows remote command execution.

How can attackers exploit this vulnerability?

By installing a malicious Git hook via a specially crafted patch.

What actions should organizations take?

Upgrade to version 1.27.1, check accounts and review logs.

Can external users take advantage of this without an account?

Yes, if open self-registration is enabled, new accounts can be created to exploit the vulnerability.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED