security1 distinct publisher
Default self-registration hands unauthenticated attackers Gitea's exploited RCE on 8,393 servers
Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.
Publishers:bleepingcomputer.com
Reality
- Evidence64
- Adoption71
- Hype gap+9
- Incentives40