Key Takeaways
- Gitea is a code-hosting platform used by many engineering teams to store and manage software, similar to GitHub.
- Three serious vulnerabilities were disclosed and tracked under three separate CVE identifiers. One is already being exploited to compromise servers and install cryptocurrency-mining software.
- Organizations running Gitea that have not confirmed their systems are updated should treat this as an immediate priority.
- Dataminr provided alerts and notification to customers about these critical vulnerabilities and exploits weeks ahead of CISA adding these CVEs to the KEV catalog.
The Three Vulnerabilities
- CVE-2026-59774 — exposes private files with no login required. This flaw allows anyone, without an account or credentials, to retrieve files from the server that should be private. This includes a configuration file that can contain passwords and access keys. Fixed in version 1.27.1.
- CVE-2026-60004 — allows full control of the server. This is the vulnerability currently being exploited. An attacker with only basic access (in some configurations, simply by creating an account) can execute their own commands on the server, with the same level of control as someone at the keyboard. This is the mechanism attackers have used to install cryptocurrency-mining software on compromised systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation and directed federal agencies to remediate by August 28. Fixed in version 1.27.1.
- CVE-2026-20896 — allows impersonation of any user, including administrators. This flaw is specific to Gitea deployments running on Docker. A misconfiguration in the default setup allowed an attacker to be authenticated as any user, including an administrator, without a password. Fixed in versions 1.26.3/1.26.4 — a separate, earlier fix from the two vulnerabilities above.
Dataminr Detection
Dataminr detected both CVE-2026-60004 and CVE-2026-20896 across their lifecycles, in each case giving customers lead time ahead of the public/mandatory-action moment.
CVE-2026-20896 – 32 days ahead of KEV
Dataminr confirmed active exploitation of CVE-2026-20896 on July 22, 2026 — 32 days ahead of CISA’s August 25 KEV action on the related CVE-2026-60004. CVE-2026-20896 has not, as of this writing, been added to the KEV catalog itself; the confirmed lead-time claim here rests on the platform’s own July 22 exploitation detection, not on any CISA action specific to this CVE. Of the two CVEs in this cluster with confirmed detection data, this is the stronger lead-time claim: over a month of advance signal before the broader KEV action that the industry treated as the trigger point.
CVE-2026-60004 – 13 days ahead of KEV
Two weaponized exploits were detected for CVE-2026-60004. One was flagged on August 12, 13 days before CISA added the CVE to the KEV, and another on August 25th about 10 hours ahead of CISA. On the following day, there was additional confirmation of active exploitation and cryptomining payloads being delivered.

Recommended Actions
- Confirm whether your organization runs Gitea. This applies only to organizations using the platform.
- Confirm the version in use. Two separate fixes apply: version 1.27.1 addresses the first two vulnerabilities; versions 1.26.3/1.26.4 or later address the third. Confirmation should specify the version number, not simply that an update occurred.
- Treat any system on an older version as an active exposure, not a routine update. Exploitation of CVE-2026-60004 is already underway. The exposure persists until the system is remediated.
- Determine whether a system may have already been compromised prior to remediation. Patching prevents future exploitation but does not reverse a prior compromise. This requires a separate review by security or IT staff.

2026 Mid-Year Threat Landscape Report
The first half of 2026 was defined by a widening gap between attack speed and defense speed — and AI is accelerating both sides. Dataminr’s 2026 Cyber Threat Landscape Mid-Year Report pulls from 4,500 threat actors tracked, 73,000 vulnerabilities detected, and over 2 million alerts processed per month to surface what actually mattered in H1 and what teams need to prepare for in H2.
Download Report