TL;DR what: CISA confirmed active exploitation of CVE-2026-60004, a CVSS 9.8 code...

Hackers are exploiting CVE-2026-60004, a critical remote code execution vulnerability affecting the Gitea development platform.

CISA adds CVE-2026-60004 to KEV amid active Gitea RCE exploitation; a separate reported attack deployed a miner-like dropper.