The Hacker News · 8/26/2026

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

CVE-2026-60004 (CVSS 9.8): Active exploitation of Gitea RCE allowing repo write-access attackers to execute arbitrary shell commands with no privilege escalation needed.

Read original coverage