← Incidents
INCIDENT 254Exploited vulnerabilityLOW / UNDER REVIEWSourced
CVE-2026-60004 added to CISA KEV: Gitea Code Injection Vulnerability
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. </p> <ul> <li><a class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" href="https://www.cve.org/CVERecord?id=CVE-2026-60004" target="_blank" title=…
Last evidence update
25 AUG 2026 · 12:00 UTC
Source count
2
Status
reported
GovernmentCVE-2026-60004
Observation history
How this record has evolved as evidence accumulated.
26 AUG · 05:17 UTC
Initial report
26 AUG · 05:17 UTC
Second independent source
26 AUG · 05:17 UTC
Summary updated from new evidence
Evidence