8,393 Gitea servers are exposed, and the flaw needs an account anyone can make
2026-08-31Security
CVE-2026-60004 lets a user with ordinary write access to a repository run shell commands as the Gitea system user. That reads as an authenticated flaw until you notice that Gitea ships with open registration, so a visitor can sign up, create a repository, and qualify. The fix has been out since 27 July. Miners are already running.