Dossier
CVE-2026-60004
Coverage of CVE-2026-60004 in the Nexus archive.
- Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation efforts targeting Gitea. The critical security flaw is identified as CVE-2026-60004, which allows for remote code execution. This vulnerability permits an attacker with ordinary write access to a repository to execute arbitrary shell commands.