Actively Exploited Gitea Flaw Enables Server Takeover and Cryptojacking
CISA has added CVE-2026-60004, a critical Gitea remote code execution vulnerability, to its Known Exploited Vulnerabilities catalog following confirmed attacks. The flaw allows users with repository write access to plant malicious Git hooks and execute commands as the Gitea service account, while default open registration can let external attackers obtain the required permissions. One reported incident involved a miner-like payload that terminated competing processes, downloaded an architecture-specific executable, and caused sustained high CPU usage. Organizations should upgrade to Gitea 1.27.1 or later, restrict account registration, and review servers for unauthorized repositories, hooks, and resource-intensive processes.
Reference: thehackernews.com