CVE-2026-60004
Known exploited · CISA KEV
CISA federal remediation date Aug 28 · date passed
Threats & Adversaries · APT / Espionage
Acronis says Red Heron exploited Gitea CVE-2026-60004 to compromise 13 organizations across six countries, starting with internet-facing code hosts and ending with stolen repositories, credentials, and persistent internal access. The victims were spread across Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka.
The group used the Gitea server as more than a source-code target: saved secrets and config files on the host let it log into other systems, keep moving, and reach root on a three-node Proxmox cluster. In plain terms, the repository server became a map and a keyring for the rest of the network.
For teams running Git hosting or Git-backed build systems, the exposure does not stop at the code server itself. If repos and build files carry reusable credentials, a single Gitea breach can inherit trust into virtualization and admin planes that were never meant to sit behind that one login.
1 source · 5h ago
Known exploited · CISA KEV
CISA federal remediation date Aug 28 · date passed
The Hacker News
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
Red Heron exploited Gitea CVE-2026-60004 to steal repositories, collect credentials, persist, and move laterally across victim networks
originalPart of the PlainSec briefing for 2026-09-14
Every edition of this story: Red Heron Turned Gitea Access into Control-Plane Breach