Code Injection in Gitea (CVE‑2026‑60004) Added to CISA KEV Catalog – Active Exploitation Threatens Git Repositories
What It Is — CISA has placed CVE‑2026‑60004, a remote code‑injection flaw in the open‑source Gitea Git service, into its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild.
Exploitability — The vulnerability is being leveraged by threat actors to achieve full control of vulnerable Gitea instances. A public exploit exists; CVSS v3.1 score is 8.8 (High).
Affected Products — Gitea (all supported versions prior to the vendor‑released patch).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Control CC6.1 (Vulnerability Management) – Demonstrating timely identification, risk‑based prioritization, and remediation of known‑exploited flaws is a core audit requirement.
- Continuous Evidence – Mapping the KEV entry to your internal asset inventory provides immutable proof that high‑risk vulnerabilities are being tracked and patched, satisfying auditors’ demand for real‑time control evidence.
- Enterprise Buyer Expectations – Federal directives (BOD 26‑04) and private‑sector contracts now require documented, risk‑based patching of KEV items; failure can stall contracts or trigger compliance findings.
Recommended Actions
- Inventory all Gitea deployments (on‑prem, cloud, containers).
- Verify version; if below the patched release, apply the vendor’s security update immediately.
- Record remediation steps in your vulnerability‑management system and capture screenshots/logs as audit evidence.
- Update your risk‑based remediation policy to flag any future KEV additions for priority handling.
- Conduct a post‑remediation validation scan to confirm the exploit is mitigated.
Source: CISA Advisory – Known Exploited Vulnerabilities Catalog, 25 Aug 2026