Security1 distinct publisher2 min readPublished
Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The chain runs from a public signup form to a shell in four steps. An attacker loads the registration page on any instance that kept the shipped default [5], creates an account, creates a repository, and thereby holds the ordinary write access the bug requires [4]. Then a patch goes to the diffpatch endpoint. Gitea's security team says that endpoint can be abused to install and execute a Git hook from repository-controlled content, and the hook runs shell commands as the Gitea OS user [6].
Gitea shipped 1.27.1 on July 27 for the flaw, which Salesforce security researcher Shai Rod reported [7][3]. Shadowserver's vulnerable count is dated August 27 [1]. That is 31 days of patch availability measured against 8,393 hosts still answering [1]. CISA's deadline for Federal Civilian Executive Branch agencies is August 28, one day after that scan, and the three-day window comes from BOD 26-04, which binds federal civilian agencies and nobody else [2][9]. The other operators in the 8,393 have no such deadline.
Gitea reports more than 400,000 installations [12]. The vulnerable figure is roughly 2 percent of that [3], but the two numbers are not the same measurement: Shadowserver counts internet-facing IPs that answer a scan [1]. An install behind a VPN with signup disabled never enters the population, so read 8,393 as exposed-and-vulnerable, not as a share of the fleet.
The advisory language says authenticated [2]. On a default install that qualifier describes nothing useful about who can reach the endpoint [5]. It does still matter on a locked-down instance, where the precondition is ordinary write access to any repository on the box [6], the level a contractor account or a stale integration token already has.
This is the second route into self-hosted Gitea worked in two months. In July, threat actors were seen abusing CVE-2026-20896, an authentication bypass in the official Gitea Docker image affecting instances with reverse proxy authentication headers enabled [11]. The payload reported on CVE-2026-60004 so far is cryptocurrency mining malware [10], installed by whichever attackers got there first; that says nothing about the ceiling on command execution as the account that serves the repositories.
Exposure here has two variables: the version the box runs, and whether a stranger can still create an account on it. A patch report shows only the first.
Ranked by verification strength, evidence, and original report placement.
CVE-2026-60004 is a code injection vulnerability that allows authenticated attackers to execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches via the diffpatch API endpoint.
Gitea's security team says the diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content, that an attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user, and that with default open registration an unauthenticated visitor can obtain the required write access by registering an account and creating a repository.
Shadowserver said it found 8,393 IPs vulnerable to CVE-2026-60004 on 2026-08-27, and warned on Friday that nearly 8,400 internet-exposed Gitea servers remain unsecured and vulnerable to ongoing attacks.
CVE-2026-60004 was reported by Salesforce security researcher Shai Rod.
Successful exploitation requires repository write access to repositories hosted on the vulnerable server.
Gitea comes with self-registration enabled by default, allowing unauthenticated attackers to register an account, create a new repository, and trigger the vulnerability without prior credentials.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
CISA's KEV triage guidance tells agencies to collect RAM before they patch1 distinct publisher
security
Johnson Controls console holds passwords in cleartext memory, and the fix line names two versions1 distinct publisher
product
CISA gives federal agencies three days to patch Ray, the framework under your ML pipelines1 distinct publisher
security
CISA logs attacks on more than 100 internet-exposed US water systems in one month1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Three named primaries, one set of eyes
Nearly everything here is first-hand from a party willing to be quoted: Gitea's security team on the Git hook abuse, Shadowserver with a date and a number, CISA with a directive and a deadline. That is unusually clean sourcing for a vulnerability story. What holds the score back is that all of it reaches us through BleepingComputer alone — nobody has re-run the scan, and the one claim with no attribution attached is the one about attacks actually happening.
The unpatched are counted; the compromised are not
What is genuinely measured in this story is exposure, not uptake: 8,393 reachable hosts on a named date, set against a claimed 400,000-plus installations and a patch order that presumes federal agencies run the software. That is more concrete than most security reporting manages. The other half of adoption — how many of those hosts were actually mined, and by whom — has no number at all.
The count is honest; the attacks are assumed
This is restrained work — the headline number is a real scan result and the timeline is arithmetic anyone can redo. The overhang sits in a single hinge: "exploited in ongoing remote code execution attacks" is doing heavy framing work while resting on unnamed reports and CISA's silence. Slightly overstated, and only there.
A breach-report pitch stapled to the last paragraph
The story ends not with reporting but with a marketing block for a vendor's 2026 simulation report and a "Get the report" call to action, which tells you something about the economics of the venue even though it touches none of the Gitea facts. Against that, the disclosure chain is unusually disinterested: a nonprofit scanner publishing raw counts, a researcher credited to his employer, and maintainers whose own quoted words make their shipped default look worse than any critic would.
Firm on the exposure, soft on the intrusion
We would stand behind the numbers, the dates and the mechanism: those are quoted from the people who produced them and internally consistent. Confidence drops on the part a reader will care about most — whether these servers are being taken over right now — because that rests on one outlet relaying reports it does not identify, with no second account anywhere in our coverage.