# Gitea vulnerabilities & exploitation

**CISA KEV**

> As of 2026-10-05, Threadlinqs tracks 6 Gitea CVEs, 1 in the CISA Known Exploited Vulnerabilities catalog, linked to 6 tracked threat campaigns and 1 named threat actor.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 6 Gitea CVEs published between 2026-06-15 and 2026-08-15. The busiest month was 2026-07 (4 new CVEs). 1 of them (17%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 6 of 6 tracked Gitea CVEs.

- [CVE-2026-60004](https://intel.threadlinqs.com/cve/CVE-2026-60004) — CRITICAL 9.8 · KEV · EPSS 24% · 2026-08-26
- [CVE-2026-20896](https://intel.threadlinqs.com/cve/CVE-2026-20896) — CRITICAL 9.8 · EPSS 0.8% · 2026-07-03
- [CVE-2026-27775](https://intel.threadlinqs.com/cve/CVE-2026-27775) — HIGH 8.8 · EPSS 0.5% · 2026-07-03
- [CVE-2026-22874](https://intel.threadlinqs.com/cve/CVE-2026-22874) — CRITICAL 9.6 · EPSS 0.5% · 2026-07-03
- [CVE-2026-58053](https://intel.threadlinqs.com/cve/CVE-2026-58053) — CRITICAL 9.9 · EPSS 0.3% · 2026-06-28
- [CVE-2026-25038](https://intel.threadlinqs.com/cve/CVE-2026-25038) — EPSS 0.2% · 2026-07-03

## Products affected

Threadlinqs normalises CPE and CNA product records across all 6 CVEs; 3 distinct Gitea products are affected. The most frequently affected:

- Open Source Git Server — 4 CVEs
- Gitea — 1 CVE
- act_runner — 1 CVE

## Threat activity

6 tracked threat campaigns reference Gitea products or exploit Gitea CVEs:

- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data](https://intel.threadlinqs.com/threat/TL-2026-2619) — CRITICAL — 2026-09-22
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — CRITICAL — 2026-09-14
- [Gitea Remote Code Execution via diffpatch Git Hook Installation (CVE-2026-60004)](https://intel.threadlinqs.com/threat/TL-2026-1767) — CRITICAL — 2026-07-29
- [Gitea CVE-2026-58443: Authorization Bypass in Pull Request Update API Enables Private Repo Access](https://intel.threadlinqs.com/threat/TL-2026-1587) — CRITICAL — 2026-07-21
- [Threat Actors Mass-Probe Gitea Docker Deployments for CVE-2026-20896 Authentication Bypass Amid Exploitarium Zero-Day Leak Wave](https://intel.threadlinqs.com/threat/TL-2026-1136) — CRITICAL — 2026-07-06
- [Gitea Container Registry Authorization Bypass (CVE-2026-27771) — Unauthenticated Pull of Private Container Images Across 31,000+ Self-Hosted Instances](https://intel.threadlinqs.com/threat/TL-2026-0602) — HIGH — 2026-05-27

## Threat actors targeting Gitea

Named threat actors attributed to campaigns that involve Gitea products or CVEs, with the number of linked campaigns:

- [Kapibala](https://intel.threadlinqs.com/actor/Kapibala) — 1 campaign

## How to prioritise Gitea patching

This order follows the data Threadlinqs holds for Gitea, not a generic severity checklist:

- 1 of 6 Gitea CVEs (17%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2026-60004](https://intel.threadlinqs.com/cve/CVE-2026-60004).
- Outside KEV, the highest EPSS scores are [CVE-2026-20896](https://intel.threadlinqs.com/cve/CVE-2026-20896) (0.8%), [CVE-2026-27775](https://intel.threadlinqs.com/cve/CVE-2026-27775) (0.5%), [CVE-2026-22874](https://intel.threadlinqs.com/cve/CVE-2026-22874) (0.5%).
- 4 CVEs score Critical and 1 High on CVSS v3 (maximum 9.9, average 9.6); sequence these after KEV and high-EPSS items.
- 4 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/gitea
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
