26 August 2026
Reference: CVE-2026-60004
1. What is being reported?
The vulnerability allows attackers to inject and execute malicious code remotely through Gitea, which is software often used to host and manage code repositories. This flaw is already being exploited in the wild, meaning hackers are actively using it to attack systems.
2. What this means in plain English
If your organisation uses Gitea, this vulnerability could let attackers take control of your system or steal sensitive information. This is a high-risk issue because it can be exploited without needing physical access or complex hacking skills.
3. Could this affect a small business?
Small businesses, charities, clubs, or trustees using Gitea software are at risk, especially if their Gitea instance is accessible over the internet. Organisations not using Gitea or similar code hosting tools are unlikely to be affected.
4. What to do now
- Check if your organisation uses Gitea software for code management.
- Contact your IT provider or software supplier to confirm if your Gitea version is vulnerable.
- Apply any security updates or mitigations provided by the Gitea vendor immediately.
- If updates are not available, consider disabling or discontinuing use of Gitea until it is safe.
5. Ask your IT provider
Can you confirm if our Gitea software is affected by the CVE-2026-60004 vulnerability and what steps have been taken to protect us?
6. Bottom line
If you use Gitea, act now to apply fixes or stop using it to avoid serious security risks.
Information based on CISA Known Exploited Vulnerabilities list and reputable security news reports.