CISA flags a critical Gitea code injection bug that attackers are using to drop crypto miners on exposed servers.
CVE-2026-60004 lets a repository writer plant a git hook and run commands as the Gitea service account.
Attackers are actively exploiting CVE-2026-20896, a critical Gitea Docker authentication bypass that grants full repository access with a single HTTP…