Index
Search
Search the public record. Drafts and scheduled notes are not included.
Critical
threats
The Gitea diffpatch bug is listed by CISA
CVE-2026-60004 lets a user with repository write access run commands as the Gitea service account. Fixed in 1.27.1 on 27 July 2026. CISA listed it on 25 August 2026. NVD scores it 9.8 and does not mention the write-access requirement.
Published 2h ago
CriticalActive ExploitationKEV
CVE-2026-60004
Gitea diffpatch Git hook code execution
RCE
Published 27 Jul 2026