← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 25, 2026 · 18:40via Malware.news

Gitea security advisory (AV26-845)

Brief

Serial Number: AV26-845

Date: August 25, 2026

As of August 14, 2026, Gitea is affected by vulnerabilities in the following product:

  • Gitea
  • Prior to 1.27.1

On August 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-60004 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

  • Remote Code Execution via diffpatch Git Hook Installation
  • Gitea 1.27.1 is released
  • Gitea 1.27.2 is released
  • CISA KEV: CVE-2026-60004

Gitea security advisory (AV26-845) - Canadian Centre for Cyber Security

Read more on Malware.news