Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Over 8,300 Gitea servers vulnerable to code execution attacks

    August 29, 2026

    Brave browser adds email aliases to help users evade tracking

    August 29, 2026

    Letters to the Standing Committee on Public Safety and National Security and Standing Committee on National Security, Defence and Veteran Affairs on NSIRA’s observations and recommendations regarding potential opportunities to further strengthen its legislative framework and governance structure

    August 29, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Over 8,300 Gitea servers vulnerable to code execution attacks
    News

    Over 8,300 Gitea servers vulnerable to code execution attacks

    adminBy adminAugust 29, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Gitea

    Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver.

    The code injection vulnerability (CVE-2026-60004) targeted in these attacks was reported by Salesforce security researcher Shai Rod, and it allows authenticated attackers to execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches via the diffpatch API endpoint.

    While successful exploitation requires repository write access to repositories hosted on vulnerable servers, Gitea comes with self-registration enabled by default, allowing unauthenticated attackers to register an account, create a new repository, and trigger the vulnerability without prior credentials.

    image

    “Gitea’s diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content. An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user,” Gitea’s security team explains. “With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository.”

    Gitea released version 1.27.1 on July 27 to address CVE-2026-60004 and advised users to upgrade their servers as soon as possible.

    On Friday, Internet security watchdog group Shadowserver warned that nearly 8,400 Gitea servers exposed online are still unsecured and remain vulnerable to ongoing attacks.

    “We are scanning/reporting Gitea instances vulnerable to CVE-2026-60004 (code injection), with 8393 IPs found vulnerable on 2026-08-27,” Shadowserver said.

    Vulnerable Gitea intsances
    Vulnerable Gitea instances (Shadowserver)

    ​On Tuesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added the vulnerability to its catalog of actively exploited flaws and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their servers within three days, by August 28, as mandated by Binding Operational Directive (BOD) 26-04.

    While the cybersecurity agency has yet to share further details on attacks targeting this flaw, the move was likely prompted by reports of in-the-wild exploitation, in which the attackers are deploying cryptocurrency mining malware on unpatched Gitea servers.

    “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” CISA warned.

    In July, threat actors were also spotted abusing another critical vulnerability (CVE-2026-20896) in the official Gitea Docker image, an authentication bypass flaw affecting Gitea instances with reverse proxy authentication headers enabled.

    Gitea is a self-hosted alternative to cloud-hosted GitHub, GitLab, and Bitbucket code hosting and DevOps platforms, with more than 400,000 installations and nearly 1,500 contributors.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleBrave browser adds email aliases to help users evade tracking
    admin
    • Website

    Related Posts

    News

    Brave browser adds email aliases to help users evade tracking

    August 29, 2026
    News

    Letters to the Standing Committee on Public Safety and National Security and Standing Committee on National Security, Defence and Veteran Affairs on NSIRA’s observations and recommendations regarding potential opportunities to further strengthen its legislative framework and governance structure

    August 29, 2026
    News

    Thousands of Interstellar Objects May Be Lurking in Our Solar System

    August 29, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    Over 8,300 Gitea servers vulnerable to code execution attacks

    August 29, 2026

    Brave browser adds email aliases to help users evade tracking

    August 29, 2026

    Letters to the Standing Committee on Public Safety and National Security and Standing Committee on National Security, Defence and Veteran Affairs on NSIRA’s observations and recommendations regarding potential opportunities to further strengthen its legislative framework and governance structure

    August 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.