Critical Gitea Vulnerability CVE-2026-60004 Allows Repository Writers to Execute Commands via Git Hooks
A critical vulnerability catalogued as CVE-2026-60004 in Gitea allows a user with write permissions on a repository to execute arbitrary commands on the server hosting the platform.
The issue arises from the abuse of Git hooks, small scripts that Git can automatically launch at different stages of the development cycle and that can be turned into a vector for injecting system commands.
The key requirement is authenticated access: the attack cannot be launched by an anonymous user and instead needs an account capable of pushing changes, for example a collaborator or any role granted write permissions. This scenario occurs frequently in projects involving multiple teams, repositories shared with third parties, or environments where broad permissions are granted for convenience.
The risk becomes especially severe in organizations that rely on Gitea as part of their internal tooling. The server often maintains visibility into the corporate network, access to shared storage, and proximity to secrets that power daily operations, ranging from access tokens for repositories and container registries to CI/CD credentials and keys used in automated deployments.
The priority response consists of applying the security update; Gitea 1.27.1 is cited as the patched version. Administrators should immediately review the attack surface introduced by Git hooks, disable them if they are not essential, and restrict their use to the minimum required scope. It is also necessary to audit repositories that accept external collaborators, tighten write permissions, and inspect hook-related storage for unauthorized scripts if any anomalous activity is detected.
The existence of a publicly available proof-of-concept raises operational urgency. When a flaw already has reproducible demonstrations, the window for reaction narrows considerably. In suspected compromise scenarios, defenders should rotate credentials and tokens that the Gitea server could access, especially those linked to automation and deployments.
Related articles
RCE Vulnerability in AI Code Editors Cursor, VS Code and Google Antigravity Threatens 50 Million Developers
Researchers at AISLE discovered a critical remote code execution vulnerability affecting the AI-powered code editors Cursor, Microsoft Visual Studio Code and Google Antigravity. The flaw allowed attackers to achieve RCE simply by tricking a developer into opening a specially crafted link embedded in a Git commit message. Successful exploitation granted full access to API keys, local files, and the ability to install persistent malware without any visible indicators. The issue stemmed from shared architectural components inherited from the Visual Studio Code codebase, which Cursor and Google Antigravity both adopted. All three vendors have released patches, yet the incident highlights systemic supply-chain risks in the rapidly growing AI-IDE ecosystem. Approximately 50 million developers were potentially exposed before fixes were deployed.
NEOMSA APIM 4.6.0 Eliminates All Critical and High Vulnerabilities Registered in FSTEC BDU
Neoflex has released NEOMSA APIM 4.6.0 with a primary focus on strengthening the security of the platform's supply chain. The team generated an SBOM in CycloneDX format, scanned components and dependencies using Grype, and cross-referenced findings against the FSTEC BDU database. This process reduced total registered vulnerabilities from 57 to 7, completely removing all 10 Critical and 24 High issues. The platform now meets the formal Security Gate criterion requiring zero Critical or High vulnerabilities from the FSTEC database in the final build. Remaining Medium findings are documented and tracked for future updates. The release provides customers with a verified, transparent component inventory that simplifies compliance and integration reviews.
Cisco Publishes 12 Security Advisories Fixing Critical Flaws in Catalyst SD-WAN and IOS XE
Cisco Systems released 12 new security advisories on August 5, 2026, disclosing a total of 23 vulnerabilities across multiple products. Two advisories covering Cisco Catalyst SD-WAN Software and Cisco IOS XE Software received the highest Critical severity rating. The SD-WAN advisory addresses five issues, including CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, each scoring 9.9 on CVSSv3.1. The IOS XE advisory details seven vulnerabilities, with CVE-2026-20272 rated 9.8 and CVE-2026-20267 rated 9.0. Additional advisories cover flaws in Integrated Management Controller, RoomOS, and Terminal Services Agent. Organizations are urged to apply the hardening releases immediately to mitigate remote exploitation risks.
Head Mare Hackers Exploit TrueConf Servers to Distribute PhantomCore and PhantomGraph Backdoors
Russian organizations have been targeted in a new campaign by the Head Mare group, which compromises unpatched TrueConf servers to deliver backdoors. Attackers chain vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with maximum privileges on affected servers. They then replace a server file with a web shell to explore the victim's infrastructure, access the TrueConf database, and substitute the client installer. Victims are tricked via social engineering into downloading the malicious client during video conferences without any suspicious emails. The campaign affects TrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier releases. Kaspersky researchers recommend immediate updates to patched versions 5.3.9, 5.4.9, and 5.5.5 released on 18 June 2026. The threat extends beyond direct TrueConf users, as any employee invited to a compromised server can inadvertently install the backdoor.