top of page
perceptive_background_267k.jpg

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Published:

26 augustus 2026 om 08:27:07

Alert date:

26 augustus 2026 om 10:00:51

Source:

thehackernews.com

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities, Ransomware & Malware

CISA has issued a warning about active exploitation of a critical remote code execution vulnerability in Gitea, tracked as CVE-2026-60004 with a CVSS score of 9.8. The flaw allows an attacker with ordinary write access to a repository to execute arbitrary shell commands. Reported attacks are dropping a miner-like payload on compromised systems. The vulnerability has been recently patched, but active exploitation campaigns are already underway. Organizations using Gitea are urged to apply the patch immediately given the severity and active exploitation status.

Technical details

Mitigation steps:

Affected products:

Gitea

Related links:

Related CVE's:

Related threat actors:

IOC's:

Sustained CPU usage exceeding 70% on servers running Gitea, Dropper script clearing LD_PRELOAD and LD_LIBRARY_PATH environment variables, Dropper script fetching architecture-specific payloads from remote locations, Execution of a binary written to disk followed by immediate deletion, Unexpected new user registrations and repository creation on Gitea instances, Suspicious Git hook files planted in repositories, Malicious requests to the /diffpatch API endpoint

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page