- Sources: BleepingComputer
- Summary: BleepingComputer reports CISA added CVE-2026-60004 in Gitea to its Known Exploited Vulnerabilities catalog after exploitation was observed in the wild. Binding operational directive BOD 26-04 requires federal civilian agencies to patch by 2026-08-28. Gitea released 1.27.1 on 2026-07-27 to address the flaw. The affected version range is not stated by the available source.
- Why it matters: A self-hosted Gitea that has not applied 1.27.1 is exposed to arbitrary shell commands as the Gitea OS user, and that release has been available for a month.
- Follow-up: Replace the news link with the Gitea security advisory and the CISA KEV entry, neither of which resolved on this run, and record the affected version range they state.
send feedback on this story