Government Advisory

CISA Flags Actively Exploited Gitea Vulnerability — Patch Now

CISA · 25 Aug 2026
Key Takeaway If your business uses Gitea, check your version now and apply the latest security patch immediately to avoid falling victim to active attacks.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new flaw, CVE-2026-60004, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects Gitea, a self-hosted platform used by many organisations to manage software code, and allows attackers to inject and run malicious code on affected systems.

CISA only adds vulnerabilities to this catalog when there is confirmed evidence they are being actively exploited by cybercriminals, making this a genuine and current threat rather than a theoretical risk. While the directive requiring rapid patching (BOD 26-04) technically applies to US federal agencies, the underlying message is relevant to any business: vulnerabilities on this list are being used in real attacks right now, and delaying patches increases risk significantly.

Australian small businesses that use Gitea for code hosting or development work should check whether they are running an affected version and apply the vendor's security update as soon as possible. Attackers often specifically target software known to appear on public exploited-vulnerability lists, since it signals an easy way in.

vulnerability management Gitea CISA KEV catalog

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.