CVE-2026-60004Critical· 9.8▾ Hadal⚠ Exploited in the wild0dayPoC availableGitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 17.4 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Federal remediation due Aug 28, 2026
Disclosed via CVEORG
Last analysed / modified upstream
87%
10 GitHub repos · Nuclei ×1 (last check)
Added to the CISA catalog on Aug 25, 2026. Federal remediation due Aug 28, 2026. View catalog ↗
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Gitea >= 1.17 < 1.27.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
gitea.dev >= 1.17.0, < 1.27.1Patched in:
gitea.dev 1.27.1Connected by shared product, vendor, weakness, or advisory.
CVE-2023-3519Critical· 9.8Unauthenticated remote code execution
CVE-2021-44529Critical· 9.8A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
CVE-2021-22205Critical· 10.0An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9
CVE-2025-14576High· 7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick
CVE-2025-67038Critical· 9.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3
CVE-2024-6886Critical· 10.0Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.