Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
CVE-2026-60004 (CVSS 9.8): Active exploitation of Gitea RCE allowing repo write-access attackers to execute arbitrary shell commands with no privilege escalation needed.
Read original coverage