CISA Flags Actively Exploited Gitea Vulnerability — Patch Now
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new flaw, CVE-2026-60004, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects Gitea, a self-hosted platform used by many organisations to manage software code, and allows attackers to inject and run malicious code on affected systems.
CISA only adds vulnerabilities to this catalog when there is confirmed evidence they are being actively exploited by cybercriminals, making this a genuine and current threat rather than a theoretical risk. While the directive requiring rapid patching (BOD 26-04) technically applies to US federal agencies, the underlying message is relevant to any business: vulnerabilities on this list are being used in real attacks right now, and delaying patches increases risk significantly.
Australian small businesses that use Gitea for code hosting or development work should check whether they are running an affected version and apply the vendor's security update as soon as possible. Attackers often specifically target software known to appear on public exploited-vulnerability lists, since it signals an easy way in.