← Back to News
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload --> #1 Trusted Cybersecurity News

Platform Followed by 5.70+ million      Get the Latest News Home

Newsletter Webinars Home Threat Intelligence Vulnerabilities Cyber Attacks Webinars Expert Insights Awards 

  Resources Webinars Awards Free eBooks About Site About THN Jobs Advertise with us Contact/Tip Us

 Reach out to get featured—contact us to send your exclusive story idea, research, hacks, or ask us a

question or leave a comment/feedback! Follow Us On Social Media      

RSS Feeds  Email Alerts Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Ravie LakshmananAug 26, 2026Vulnerability / Cryptojacking The U.S. Cybersecurity and Infrastructure

Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security

flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution

that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the Gitea OS

user. "Gitea's diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content,"

according to an advisory released by Gitea last month. "With default open registration, an unauthenticated visitor can

obtain the required write access by registering an account and creating a repository." Security researcher Shai rod (aka

NightRang3r) has been credited with discovering and reporting the issue. The issue affects all versions of Gitea from

version 1.17 and has been patched in version 1.27.1. As The Hacker News reported previously, while the vulnerable API

call requires authentication and repository write permission, the fact that Gitea allows registration by default makes

it possible for an external actor to create an account and a repository and then trigger the exploit without having to

rely on pre-existing credentials. "Gitea contains a code injection vulnerability that allows an attacker with repository

write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell

commands as the Gitea service account," CISA said. The agency, which added the flaw to its Known Exploited

Vulnerabilities (KEV) catalog, did not disclose any details of how the security flaw has been exploited in the wild or

who is behind the efforts. However, a full-stack developer named Andrey (aka @Causelof) pointed out in an analysis

published last week on the Russian blogging platform Habr that their Gitea instance was targeted by an unknown threat

actor using CVE-2026-60004 to deploy a cryptocurrency-miner-like dropper. The incident came to light after receiving an

email notification from hosting provider HOSTKEY, stating their virtual server had been using more than 70% of the

processor capacity for an extended period of time in violation of the service's terms, causing the provider to

temporarily limit the available CPU resources to the VPS. Specifically, the user cited the following configuration as

responsible for driving the activity - DISABLE_REGISTRATION = false (If the parameter is enabled, only an admin can

create accounts for users) REGISTER_EMAIL_CONFIRM = false (If the parameter is enabled, it asks for registration

confirmation via email) ENABLE_OPENID_SIGNUP = true (The parameter allows registering via OpenID) REQUIRE_SIGNIN_VIEW =

false (If the parameter is enabled, it forces users to log in to view any page or to use API) "The fact that open

registration is enabled here is significant precisely because of its connection to the vulnerability," Andrey noted. "A

new user could register, create their own repository, and obtain the necessary write permissions within it. Gitea's SSH

was not exposed to the outside world. The attack vector was via HTTPS." Before deploying the miner-like payload, the

dropper script is said to have undertaken the following steps - Clear LD_PRELOAD and LD_LIBRARY_PATH Search for

processes with high CPU usage Attempt to kill competing processes Fetch the payload based on the system architecture

Download, write it to a location on disk, and run it Delete the file after execution The exact nature of the next-stage

payload is unknown, as the developer said they did not conduct an analysis of its contents, adding "I do not have

confirmed information regarding the mining pool, wallet, miner family, or specific operator." However, the spike in CPU

usage lines up with a cryptojacking campaign targeting vulnerable Gitea instances. It's unclear if CISA added the flaw

to the KEV catalog because of this specific attack, or if it has uncovered evidence of exploitation targeting unpatched

Gitea servers in the U.S. Federal agencies are required to patch the flaw by August 28, 2026, while prioritizing updates

based on a risk-based approach. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read

more exclusive content we post. SHARE     Tweet Share Share

Share  Share on Facebook Share on Twitter Share on Linkedin Share on

Reddit Share on Hacker News Share on Email Share on WhatsApp Share on Facebook Messenger

Share on Telegram SHARE  Application Security, cryptojacking, Cyber Attack, DevOps, exploit, Open

Source, remote code execution, Vulnerability ⚡ Top Stories This Week Microsoft Patches Severe Entra ID Flaw (CVSS

10.0) Allowing Remote Code Execution ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit,

and More New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data Zombie Card Attack Can

Revive Expired Visa Cards for Contactless Payments CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS

Amplification Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices Cloudflare Workers

Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second OpenAI Pauses Frontier RL Training as It Tightens

Defenses Against Unsafe AI Behavior Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses,

and P2P Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps AI "Mind Viruses" Can

Spread Between Agents Through Persistent Prompt Files SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly

40,000 Customers Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects ⚡ Weekly

Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More Unisoc VoLTE Video Call Exploit Chain Can

Give Attackers Full Android Kernel Access Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5

Proxies SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch Hackers Spend Nearly $7

Million on Expired Domains to Redirect Traffic to Scams and Malware Apple Warns Users in 110 Countries They May Be

Targets of Mercenary Spyware Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups GeoServer

Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE Attackers Exploit SharePoint Authentication Bypass

After Public PoC Release Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor Attackers Exploit

VMware vCenter Vulnerability to Gain Persistent Remote Access ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch

Bypass With SYSTEM Access ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials

Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever —

Read the New Report Build AI Agents and Automations Without Losing Security Control Cybersecurity Webinars AI Attacks

Are Moving Faster. Watch: How to Prepare Your Security Program for AI-Powered Attacks AI can find and chain

vulnerabilities in minutes. This session gives you a practical roadmap to strengthen visibility, response, and

remediation. Register See What 300 Leaders Found Shipping 10–50× More Code? Learn How to Keep Security in

Control AI is helping teams ship code 10–50× faster. This session shows how to keep security from falling

behind. Register ⚡ Latest News Cybersecurity Resources 11 Real Stories: How Identity Exposure Unlocks Active

Attack PathsMap cross-domain privilege escalation to sever breach routes at key choke points. Promoted to Lead a Team

You Can't Yet Speak To?Build the technical fluency to manage security programs. GSLC leadership training at SANS CDI. AI

Adoption Is Outpacing Governance, New SANS Survey FindsSee where 536 security pros say AI programs are falling short.

​ Expert Insights Articles Videos Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure

August 24, 2026 Read ➝ Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals

August 24, 2026 Read ➝ The Long Road From Pentest Finding to Verified Fix August 17, 2026 Read

➝ Why Your AI Developer Tools Might Be Your Biggest Security Risk August 17, 2026 Read ➝ Get the

Latest News in Your Inbox Get the latest news, expert insights, exclusive resources, and strategies from industry

leaders, all for free. Email Connect with us! 2,000,000 Followers 725,000 Followers 25,500

Subscribers 172,000 Followers 1,990,000 Followers 60,000 Followers Company About THN Advertise with us

Contact Pages Webinars Awards Privacy Policy  RSS Feeds  Contact Us © 2026 The Hacker News. All

Rights Reserved.

Source: thehackernews.com