CISA says attackers are exploiting a critical Gitea code-injection flaw
CISA says CVE-2026-60004 is being exploited on self-hosted Gitea: a critical code injection in the diffpatch API. Default open registration lets an unauthenticated visitor create an account and repository, then run commands as the gitea user.


