US cybersecurity authorities have issued a warning about a critical vulnerability in Gitea systems after discovering that a group of hackers is exploiting the flaw to covertly run cryptocurrency mining scripts. The incident has raised serious security concerns for organizations that manage their own servers, which must urgently update their systems before the end of August 2026 to prevent damage to business data and assets.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability tracked as CVE-2026-60004 to its catalog of urgent threats. The decision follows a surge of heavy attacks by hackers against the Gitea open-source code management system. Cybercriminals are employing remote command execution techniques to take control of malware that uses servers for cryptocurrency mining.
Zeljka Zorz, editor-in-chief of a security media outlet, identified the root cause of the problem as a weakness in older versions of the system. A developer in Russia disclosed a real-world incident on the Habr web forum, revealing that their server had fallen victim to an automated account-registration bot. The attacker created a repository and then triggered the vulnerability to successfully execute malicious commands in just 11 seconds.
This attack granted the hackers elevated privileges equivalent to those of an operating system administrator. The malware covertly downloaded a hidden set of commands and a coin-mining program to seize processing power. Although the application was running in an isolated Docker container environment, the abnormally heavy CPU load compelled the hosting provider to immediately alert the platform owner.
This phenomenon serves as a danger signal for businesses and agencies that manage their own IT infrastructure. Opening up free user registration without any identity verification mechanism is a critical weak point that organizational executives must urgently review. Cybersecurity teams should move quickly to upgrade the software to version 1.27.2, while also disabling user registration and purging all old passwords entirely.
CISA has issued a firm directive requiring federal government agencies to patch this vulnerability by 28 August 2026. This direction reflects the broader market reality that cybercriminals continue to be attracted to plundering organizational resources to mine Bitcoin and other cryptocurrencies. Technology companies and financial institutions need to elevate their defenses to the highest level in order to maintain stability and long-term investor confidence.






