HackerFeeds

CyberSecurity News

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

The Hacker News
· August 26, 2026

AI summary

The US Cybersecurity and Infrastructure Security Agency has warned of active exploitation of a critical security flaw in Gitea. The vulnerability, which has a CVSS score of 9.8, allows for remote code execution and enables an attacker with ordinary write access to a repository to execute arbitrary shell commands. This flaw is being exploited to drop a miner-like payload. The issue is identified as CVE-2026-60004. The vulnerability has been recently patched.

Read the full article at The Hacker Newsthehackernews.com/2026/08/critical-gitea-rce-actively-exploited.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.