Skip to content
Breaking
1.8% more PhD candidates in 2025Microsoft tests new privacy controls for Windows 11 desktop appsHackers now exploit critical Gitea flaw in code injection attacksInheritance and gift tax set to reach new high of 21.4 billion euros in 2025SOCs swap alert queues for AI-driven hypothesis enginesOwner of Indonesian coal mining giant Bayan in talks on saleClaude Opus 4.6 agent cancels gym reservation in nine of ten synthetic testsMeet kids' protein needs without expensive foodsXMUM students win bronze in medical innovation competitionFlash flood on Nepal-Tibet border kills 19, 384 missing including touristsIJM posts 43.7% rise in quarterly profit on construction surge, declares 10 sen dividendLegato raises $12 million to launch AI hearing glassesTop five finish at national engineering competition for XMUM studentSingaporean jailed 23 days for 1,000 silent calls to policeIJM names Lee Teck Yuen chairman as Krishnan Tan retiresRunable raises $21m to help small businesses grow with AI agentsAI models flub these intelligence tests. Can you fare any better?Malaysian firms warned against rushing AI model choices for security operationsMudslide from Nepal kills several at Gyirong Port trade hubUS Cold War aid turned Thailand into a regional growth hub1.8% more PhD candidates in 2025Microsoft tests new privacy controls for Windows 11 desktop appsHackers now exploit critical Gitea flaw in code injection attacksInheritance and gift tax set to reach new high of 21.4 billion euros in 2025SOCs swap alert queues for AI-driven hypothesis enginesOwner of Indonesian coal mining giant Bayan in talks on saleClaude Opus 4.6 agent cancels gym reservation in nine of ten synthetic testsMeet kids' protein needs without expensive foodsXMUM students win bronze in medical innovation competitionFlash flood on Nepal-Tibet border kills 19, 384 missing including touristsIJM posts 43.7% rise in quarterly profit on construction surge, declares 10 sen dividendLegato raises $12 million to launch AI hearing glassesTop five finish at national engineering competition for XMUM studentSingaporean jailed 23 days for 1,000 silent calls to policeIJM names Lee Teck Yuen chairman as Krishnan Tan retiresRunable raises $21m to help small businesses grow with AI agentsAI models flub these intelligence tests. Can you fare any better?Malaysian firms warned against rushing AI model choices for security operationsMudslide from Nepal kills several at Gyirong Port trade hubUS Cold War aid turned Thailand into a regional growth hub
AI Edge

Hackers now exploit critical Gitea flaw in code injection attacks

Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]

Source: BleepingComputer · August 26, 2026 at 1:04 PM · AI-assisted report

Single-source

KUALA LUMPUR, 26 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Share

Hackers Exploit Critical Gitea Flaw in Code Injection Attacks, CISA Warns

Market Impact

KUALA LUMPUR, Aug 26 — Cybersecurity authorities are warning of active exploitation of a critical-severity vulnerability in Gitea, a self-hosted Git service widely used by developers for version control and DevOps workflows. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw, tracked as CVE-2026-60004, to its Known Exploited Vulnerabilities (KEV) catalog and mandated U.S. federal agencies to patch affected systems within three days.

The vulnerability, reported by Salesforce security researcher Shai Rod, allows authenticated users with repository write access—or even unauthenticated attackers on default-configured instances—to execute arbitrary shell commands with the privileges of the Gitea service account. This is achieved by submitting malicious patches via the diffpatch API endpoint. Gitea’s security team confirmed that the flaw can be abused to install and execute Git hooks from repository-controlled content, enabling full system compromise.

Gitea released version 1.27.1 on July 27 to address CVE-2026-60004, urging users to upgrade immediately. Despite the patch, cybersecurity firm Shadowserver reports nearly 5,000 Gitea instances remain exposed online, though it remains unclear how many have been secured or are being used as honeypots. CISA’s inclusion of the flaw in the KEV catalog follows evidence of active exploitation in the wild, including the deployment of cryptocurrency mining malware on unpatched servers.

This marks the second critical Gitea vulnerability exploited in recent months. In July, threat actors targeted instances with reverse proxy authentication headers enabled, exploiting CVE-2026-20896, an authentication bypass flaw. Security experts warn that once attackers gain valid credentials, traditional prevention measures become less effective, highlighting the need for layered defenses.

For the Malaysian market, the risk is particularly relevant to organizations using self-hosted Git solutions for software development. While CISA’s directive applies only to U.S. federal agencies, the agency has urged all organizations to prioritize remediation of KEV catalog vulnerabilities. Industry observers note that many Malaysian enterprises, particularly in tech, finance, and government-linked sectors, rely on self-hosted Git platforms for internal collaboration and code management.

Industry analysts suggest that the exploitation of such flaws underscores broader challenges in open-source software security, where community-driven projects may lack patching cycles. Gitea, while popular for its lightweight and self-hosted nature, has faced increasing scrutiny as its user base grows. The rapid addition of CVE-2026-60004 to the KEV catalog reflects growing concerns over supply-chain risks in DevOps environments.

Looking ahead, security teams are advised to audit their Gitea deployments, disable open registration where unnecessary, and apply the latest patches promptly. The incident serves as a reminder of the persistent threat posed by unpatched software, even in niche but critical infrastructure components. Organizations are encouraged to adopt proactive vulnerability management strategies to mitigate risks associated with code injection and privilege escalation attacks.

Related: Gitea · Shai Rod · Kuala Lumpur

Reporting based on BleepingComputer. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.