HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Code Injection in Gitea (CVE‑2026‑60004) Added to CISA KEV Catalog – Active Exploitation Threatens Git Repositories

CISA has listed CVE‑2026‑60004, a remote code‑injection bug in Gitea, in its Known Exploited Vulnerabilities catalog after observing active attacks. Organizations must prioritize remediation to satisfy SOC 2 vulnerability‑management controls and maintain audit‑ready evidence.

LiveThreat™ Intelligence · 📅 August 26, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Code Injection in Gitea (CVE‑2026‑60004) Added to CISA KEV Catalog – Active Exploitation Threatens Git Repositories

What It Is — CISA has placed CVE‑2026‑60004, a remote code‑injection flaw in the open‑source Gitea Git service, into its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild.

Exploitability — The vulnerability is being leveraged by threat actors to achieve full control of vulnerable Gitea instances. A public exploit exists; CVSS v3.1 score is 8.8 (High).

Affected Products — Gitea (all supported versions prior to the vendor‑released patch).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Control CC6.1 (Vulnerability Management) – Demonstrating timely identification, risk‑based prioritization, and remediation of known‑exploited flaws is a core audit requirement.
  • Continuous Evidence – Mapping the KEV entry to your internal asset inventory provides immutable proof that high‑risk vulnerabilities are being tracked and patched, satisfying auditors’ demand for real‑time control evidence.
  • Enterprise Buyer Expectations – Federal directives (BOD 26‑04) and private‑sector contracts now require documented, risk‑based patching of KEV items; failure can stall contracts or trigger compliance findings.

Recommended Actions

  • Inventory all Gitea deployments (on‑prem, cloud, containers).
  • Verify version; if below the patched release, apply the vendor’s security update immediately.
  • Record remediation steps in your vulnerability‑management system and capture screenshots/logs as audit evidence.
  • Update your risk‑based remediation policy to flag any future KEV additions for priority handling.
  • Conduct a post‑remediation validation scan to confirm the exploit is mitigated.

Source: CISA Advisory – Known Exploited Vulnerabilities Catalog, 25 Aug 2026

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →