CISA has issued a warning about active exploitation of a critical remote code execution vulnerability in Gitea, tracked as CVE-2026-60004 with a CVSS score of 9.8. The flaw allows an attacker with ordinary write access to a repository to execute arbitrary shell commands. Reported attacks are dropping a miner-like payload on compromised systems. The vulnerability has been recently patched, but active exploitation campaigns are already underway. Organizations using Gitea are urged to apply the patch immediately given the severity and active exploitation status.
Sustained CPU usage exceeding 70% on servers running Gitea, Dropper script clearing LD_PRELOAD and LD_LIBRARY_PATH environment variables, Dropper script fetching architecture-specific payloads from remote locations, Execution of a binary written to disk followed by immediate deletion, Unexpected new user registrations and repository creation on Gitea instances, Suspicious Git hook files planted in repositories, Malicious requests to the /diffpatch API endpoint