


Perceptive Security
SOC/SIEM Consultancy

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Published:
26 augustus 2026 om 08:27:07
Alert date:
26 augustus 2026 om 10:00:51
Source:
thehackernews.com
Web Technologies, Zero-Day Vulnerabilities, Ransomware & Malware
CISA has issued a warning about active exploitation of a critical remote code execution vulnerability in Gitea, tracked as CVE-2026-60004 with a CVSS score of 9.8. The flaw allows an attacker with ordinary write access to a repository to execute arbitrary shell commands. Reported attacks are dropping a miner-like payload on compromised systems. The vulnerability has been recently patched, but active exploitation campaigns are already underway. Organizations using Gitea are urged to apply the patch immediately given the severity and active exploitation status.
Technical details
Mitigation steps:
Affected products:
Gitea
Related links:
https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog
https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
https://habr.com/ru/articles/1072030/
https://docs.gitea.com/administration/config-cheat-sheet/#service-service
Related CVE's:
Related threat actors:
IOC's:
Sustained CPU usage exceeding 70% on servers running Gitea, Dropper script clearing LD_PRELOAD and LD_LIBRARY_PATH environment variables, Dropper script fetching architecture-specific payloads from remote locations, Execution of a binary written to disk followed by immediate deletion, Unexpected new user registrations and repository creation on Gitea instances, Suspicious Git hook files planted in repositories, Malicious requests to the /diffpatch API endpoint
This article was created with the assistance of AI technology by Perceptive.
