Gitea CVE-2026-60004: Red Heron campaign compromises 13 orgs (Acronis TRU)
Gitea GHSA-rcr6-4jqh-j84m / CVE-2026-60004 (28 July 2026 advisory; CISA KEV 25 August 2026): diffpatch API can let a user with repository write access (including self-registered users on open instances) run commands as the Gitea service account. Affected 1.17 through versions before 1.27.1; patch to 1.27.1+. UPDATE 14 September 2026: The Hacker News cites Acronis Threat Research Unit attributing a China-linked cluster (moderate confidence) tracked as Red Heron that weaponised CVE-2026-60004 from ~29 July 2026, scanning 1,386 Gitea instances across seven countries (plus a 477-instance Taiwan dataset) and confirming compromises at 13 organisations in Canada (2), Argentina (1), Taiwan (4), the US (4), Qatar (1), and Sri Lanka (1). Campaign progressed from repository theft to credentials, persistence, and lateral movement (including root on a three-node Proxmox cluster). Tooling includes C++ Linux implant JITTERLY (30+ commands; overlaps AdaptixC2) and LD_PRELOAD rootkit SIXZUT. Primary remains Gitea advisory; secondary: THN / Acronis TRU reporting. Distinct from generic KEV listing alone.
- Product
- Gitea
- Versions
- 1.17 through versions before 1.27.1
- CVSS
- (CVSS 3.1, GitHub CNA)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- 1.27.1
Primary: Gitea advisory GHSA-rcr6-4jqh-j84m / CVE-2026-60004 · Vendor: NVD · CVE: CVE-2026-60004 · The Hacker News — Red Heron / Acronis TRU (14 Sep 2026)
