CVE-2026-60004 turns Gitea's diffpatch API into remote code execution for anyone who can register an account. The fix is three steps, and CISA's federal deadline is August 28, 2026.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.
Perspective Coverage
7 publishers
- Builder
- Builder 22%
- Operator
- Operator 67%
- Investor
- Investor 11%
Reality
- Evidence62
- Adoption40
- Hype gap+20
- Incentives
- Insufficient
- Confidence58
GreyNoise traced scans from a single IP address, running since early June 2026, to a Chinese-speaking actor that breached 49 organizations through WordPress Core and stripped configs and root hashes from 996 ZyXEL switches.
Reality
- Evidence45
- Adoption68
- Hype gap+22
- Incentives55
- Confidence52
GitHub's published post-mortem traces two hours of site-wide failure on September 13 to a data-cleanup job whose only brake measured replica lag, on the cluster holding permission data that nearly every authenticated request reads.
Reality
- Evidence62
- Adoption24
- Hype gap+16
- Incentives46
- Confidence55
Acronis attributes exploitation of CVE-2026-60004 to a China-linked cluster that automated a published proof-of-concept from July 29, scanned 1,386 self-hosted Gitea servers and left a Linux rootkit behind.
Reality
- Evidence55
- Adoption40
- Hype gap+12
- Incentives60
- Confidence50
Gitea's diffpatch flaw needs repository write access, which open self-registration hands to strangers. The awkward part is that the only patched build sits in the 1.27 family, so teams pinned to 1.26.x cannot fix this in place.
Publishers:windowsforum.com
Reality
- Evidence70
- Adoption50
- Hype gap+5
- Incentives30
- Confidence62
A published Git process makes one step unskippable: testing the release-candidate branch before it lands in master. CI/CD, by the author's own account, is optional.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+18
- Incentives52
- Confidence42
A CNCF blog account reports a self-upgrading K3s control plane on Kairos with etcd quorum intact. The instructive part is that both bugs were in the automation, not the OS.
Reality
- Evidence42
- Adoption16
- Hype gap+32
- Incentives64
- Confidence52