CVE-2026-60004
Known exploited · CISA KEV
CISA federal remediation date Aug 28 · date passed
Threats · 4h ago
Acronis says Red Heron exploited Gitea CVE-2026-60004 to compromise 13 organizations across six countries, starting with internet-facing code hosts and ending with stolen repositories, credentials, and persistent internal access. The victims were spread across Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka.
The group used the Gitea server as more than a source-code target: saved secrets and config files on the host let it log into other systems, keep moving, and reach root on a three-node Proxmox cluster. In plain terms, the repository server became a map and a keyring for the rest of the network.
For teams running Git hosting or Git-backed build systems, the exposure does not stop at the code server itself. If repos and build files carry reusable credentials, a single Gitea breach can inherit trust into virtualization and admin planes that were never meant to sit behind that one login.
Known exploited · CISA KEV
CISA federal remediation date Aug 28 · date passed
1 source covering this story
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
Red Heron exploited Gitea CVE-2026-60004 to steal repositories, collect credentials, persist, and move laterally across victim networks
Part of the PlainSec briefing for 2026-09-14