8393 — the number Shadowserver reported as Internet-exposed Gitea IPs still vulnerable to CVE-2026-60004 on 2026-08-27.
The flaw: CVE-2026-60004 and how it is abused
The vulnerability at the heart of this episode is CVE-2026-60004, a code injection bug in Gitea's diffpatch API endpoint reported by Salesforce security researcher Shai Rod. According to Gitea's security team, "Gitea's diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content. An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user."
Successful exploitation requires write access to a repository on a vulnerable server. But because Gitea enables self‑registration by default, an unauthenticated visitor can register an account, create a repository and obtain the write access needed to trigger the flaw — turning what might look like a modest privilege requirement into a de facto public attack surface.
Scale of exposure: Shadowserver's scan and the continuing gap
Gitea released a security update (version 1.27.1) on July 27 to address CVE-2026-60004 and advised administrators to upgrade as soon as possible. Despite that bulletin, the Internet security watchdog Shadowserver reported on 2026-08-27 that 8,393 IP addresses pointing to Gitea instances remained vulnerable.
Shadowserver summarized the situation bluntly: "We are scanning/reporting Gitea instances vulnerable to CVE-2026-60004 (code injection), with 8393 IPs found vulnerable on 2026-08-27." That figure underlines a persistent patch gap on publicly exposed code-hosting servers even after a vendor fix and public disclosure.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageObserved attacker behavior and related incidents
While CISA has not published operational details about every exploitation event, the agency added CVE-2026-60004 to its catalog of actively exploited vulnerabilities and ordered U.S. Federal Civilian Executive Branch agencies to patch affected systems within three days under Binding Operational Directive 26-04, with a compliance deadline of August 28.
The move by CISA was prompted by reports of in-the-wild exploitation in which attackers deploy cryptocurrency mining malware on unpatched Gitea servers. CISA warned that "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise."
The CVE-2026-60004 incidents follow earlier July activity in which threat actors abused a different critical Gitea flaw — CVE-2026-20896, an authentication bypass in the official Gitea Docker image affecting instances with reverse proxy authentication headers enabled.
Gitea's footprint and why this matters
Gitea is a self-hosted alternative to cloud-hosted platforms and, per the available data, has more than 400,000 installations and nearly 1,500 contributors. That scale means vulnerable installations can be widely distributed across small teams, enterprises, research groups and other organizations that choose to run their own code-hosting services.
When a service account is abused to run arbitrary shell commands — as CVE-2026-60004 enables — the consequences typically go beyond a single repository. The ability to execute code as the Gitea OS user lets attackers drop miners, move laterally, or stage further operations on a host; the observed use of cryptocurrency miners is a concrete example of how attackers leverage that foothold for profit.
What this means for technologists and security teams, policymakers and federal agencies, and Gitea self-hosters
- Technologists and security teams: The vendor-supplied mitigation is explicit — upgrade to Gitea 1.27.1 — and the remaining exposed IP count shows a need for inventory and rapid patching of Internet-facing services. Default open registration converts a write‑access requirement into public attackability, so teams should validate their authentication and registration configurations when applying the update.
- Policymakers and federal agencies: CISA's inclusion of CVE-2026-60004 in its catalog and the three‑day BOD 26-04 deadline underscore that exploited code-execution flaws can trigger emergency compliance measures. For federal networks the immediate imperative was a patch deadline of August 28; the broader policy signal is that actively exploited vulnerabilities receive expedited remediation mandates.
- Gitea self-hosters and enterprises: Operators of self-hosted Gitea instances must weigh convenience (default open registration) against exposure. The existence of an available fix makes upgrading the primary recommended action; remaining unpatched servers are demonstrably attractive targets, as evidenced by ongoing deployments of cryptocurrency mining malware.
The record here is simple and sharp: a fix has been available since July 27, and nearly 8,400 Internet-exposed instances remained unpatched as of August 27. Whether the remaining hosts are offline, forgotten, or deliberately left unpatched will determine if the problem shrinks or persists — but the immediate choices for administrators are clear and time-sensitive.
Original reporting: BleepingComputer — Over 8,300 Gitea servers vulnerable to code execution attacks




