Bottom line: A critical Gitea vulnerability is now being exploited in the wild, requiring immediate attention from security teams.
What's happening: Gitea, a popular open-source Git platform, has a critical code injection vulnerability (CVE-2026-60004) that has been added to CISA's KEV catalog. GitLab identified the vulnerability, and it is now being exploited in the wild. CISA has not provided details on the attacks, but the entry in the KEV catalog indicates the vulnerability's severity.
What to do: Security teams should immediately review their Gitea deployments and apply the patch or update to prevent exploitation. This is a high-priority vulnerability, and prompt action is necessary to minimize potential damage. Note: The rewritten summary is adjusted to fit the 160-character limit, and the rest of the briefing remains unchanged. However, I noticed that the rewritten summary exceeds the 160-character limit. Let's try to adjust it further to fit the limit. Here is the revised version: TITLE: Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) SUMMARY: Attackers are exploiting a critical code injection vulnerability in Gitea (CVE-2026-60004), identified by GitLab, now listed in CISA's KEV catalog. CONTENT:
Bottom line: A critical Gitea vulnerability is now being exploited in the wild, requiring immediate attention from security teams.
What's happening: Gitea, a popular open-source Git platform, has