8,300+ Gitea servers remain exposed to actively exploited RCE flaw
Shadowserver reports over 8,300 internet-facing Gitea instances remain unpatched against CVE-2026-60004, a critical code injection bug already being exploited in the wild. The flaw lets an attacker with repository write access run arbitrary shell commands as the Gitea service account, and since Gitea allows open self-registration by default, unauthenticated users can create an account and repository to gain that access. Gitea patched the issue in version 1.27.1 on July 27, and CISA has added it to its known exploited vulnerabilities list, giving federal agencies just three days to remediate.