Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload --> #1 Trusted Cybersecurity News
Platform Followed by 5.70+ million Get the Latest News Home
Newsletter Webinars Home Threat Intelligence Vulnerabilities Cyber Attacks Webinars Expert Insights Awards
Resources Webinars Awards Free eBooks About Site About THN Jobs Advertise with us Contact/Tip Us
Reach out to get featured—contact us to send your exclusive story idea, research, hacks, or ask us a
question or leave a comment/feedback! Follow Us On Social Media
RSS Feeds Email Alerts Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Ravie LakshmananAug 26, 2026Vulnerability / Cryptojacking The U.S. Cybersecurity and Infrastructure
Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security
flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution
that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the Gitea OS
user. "Gitea's diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content,"
according to an advisory released by Gitea last month. "With default open registration, an unauthenticated visitor can
obtain the required write access by registering an account and creating a repository." Security researcher Shai rod (aka
NightRang3r) has been credited with discovering and reporting the issue. The issue affects all versions of Gitea from
version 1.17 and has been patched in version 1.27.1. As The Hacker News reported previously, while the vulnerable API
call requires authentication and repository write permission, the fact that Gitea allows registration by default makes
it possible for an external actor to create an account and a repository and then trigger the exploit without having to
rely on pre-existing credentials. "Gitea contains a code injection vulnerability that allows an attacker with repository
write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell
commands as the Gitea service account," CISA said. The agency, which added the flaw to its Known Exploited
Vulnerabilities (KEV) catalog, did not disclose any details of how the security flaw has been exploited in the wild or
who is behind the efforts. However, a full-stack developer named Andrey (aka @Causelof) pointed out in an analysis
published last week on the Russian blogging platform Habr that their Gitea instance was targeted by an unknown threat
actor using CVE-2026-60004 to deploy a cryptocurrency-miner-like dropper. The incident came to light after receiving an
email notification from hosting provider HOSTKEY, stating their virtual server had been using more than 70% of the
processor capacity for an extended period of time in violation of the service's terms, causing the provider to
temporarily limit the available CPU resources to the VPS. Specifically, the user cited the following configuration as
responsible for driving the activity - DISABLE_REGISTRATION = false (If the parameter is enabled, only an admin can
create accounts for users) REGISTER_EMAIL_CONFIRM = false (If the parameter is enabled, it asks for registration
confirmation via email) ENABLE_OPENID_SIGNUP = true (The parameter allows registering via OpenID) REQUIRE_SIGNIN_VIEW =
false (If the parameter is enabled, it forces users to log in to view any page or to use API) "The fact that open
registration is enabled here is significant precisely because of its connection to the vulnerability," Andrey noted. "A
new user could register, create their own repository, and obtain the necessary write permissions within it. Gitea's SSH
was not exposed to the outside world. The attack vector was via HTTPS." Before deploying the miner-like payload, the
dropper script is said to have undertaken the following steps - Clear LD_PRELOAD and LD_LIBRARY_PATH Search for
processes with high CPU usage Attempt to kill competing processes Fetch the payload based on the system architecture
Download, write it to a location on disk, and run it Delete the file after execution The exact nature of the next-stage
payload is unknown, as the developer said they did not conduct an analysis of its contents, adding "I do not have
confirmed information regarding the mining pool, wallet, miner family, or specific operator." However, the spike in CPU
usage lines up with a cryptojacking campaign targeting vulnerable Gitea instances. It's unclear if CISA added the flaw
to the KEV catalog because of this specific attack, or if it has uncovered evidence of exploitation targeting unpatched
Gitea servers in the U.S. Federal agencies are required to patch the flaw by August 28, 2026, while prioritizing updates
based on a risk-based approach. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read
more exclusive content we post. SHARE Tweet Share Share
Share Share on Facebook Share on Twitter Share on Linkedin Share on
Reddit Share on Hacker News Share on Email Share on WhatsApp Share on Facebook Messenger
Share on Telegram SHARE Application Security, cryptojacking, Cyber Attack, DevOps, exploit, Open
Source, remote code execution, Vulnerability ⚡ Top Stories This Week Microsoft Patches Severe Entra ID Flaw (CVSS
10.0) Allowing Remote Code Execution ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit,
and More New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data Zombie Card Attack Can
Revive Expired Visa Cards for Contactless Payments CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS
Amplification Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices Cloudflare Workers
Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second OpenAI Pauses Frontier RL Training as It Tightens
Defenses Against Unsafe AI Behavior Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses,
and P2P Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps AI "Mind Viruses" Can
Spread Between Agents Through Persistent Prompt Files SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly
40,000 Customers Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects ⚡ Weekly
Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More Unisoc VoLTE Video Call Exploit Chain Can
Give Attackers Full Android Kernel Access Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5
Proxies SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch Hackers Spend Nearly $7
Million on Expired Domains to Redirect Traffic to Scams and Malware Apple Warns Users in 110 Countries They May Be
Targets of Mercenary Spyware Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups GeoServer
Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE Attackers Exploit SharePoint Authentication Bypass
After Public PoC Release Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor Attackers Exploit
VMware vCenter Vulnerability to Gain Persistent Remote Access ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch
Bypass With SYSTEM Access ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials
Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever —
Read the New Report Build AI Agents and Automations Without Losing Security Control Cybersecurity Webinars AI Attacks
Are Moving Faster. Watch: How to Prepare Your Security Program for AI-Powered Attacks AI can find and chain
vulnerabilities in minutes. This session gives you a practical roadmap to strengthen visibility, response, and
remediation. Register See What 300 Leaders Found Shipping 10–50× More Code? Learn How to Keep Security in
Control AI is helping teams ship code 10–50× faster. This session shows how to keep security from falling
behind. Register ⚡ Latest News Cybersecurity Resources 11 Real Stories: How Identity Exposure Unlocks Active
Attack PathsMap cross-domain privilege escalation to sever breach routes at key choke points. Promoted to Lead a Team
You Can't Yet Speak To?Build the technical fluency to manage security programs. GSLC leadership training at SANS CDI. AI
Adoption Is Outpacing Governance, New SANS Survey FindsSee where 536 security pros say AI programs are falling short.
Expert Insights Articles Videos Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure
August 24, 2026 Read ➝ Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals
August 24, 2026 Read ➝ The Long Road From Pentest Finding to Verified Fix August 17, 2026 Read
➝ Why Your AI Developer Tools Might Be Your Biggest Security Risk August 17, 2026 Read ➝ Get the
Latest News in Your Inbox Get the latest news, expert insights, exclusive resources, and strategies from industry
leaders, all for free. Email Connect with us! 2,000,000 Followers 725,000 Followers 25,500
Subscribers 172,000 Followers 1,990,000 Followers 60,000 Followers Company About THN Advertise with us
Contact Pages Webinars Awards Privacy Policy RSS Feeds Contact Us © 2026 The Hacker News. All
Rights Reserved.
