regulator
CISA Adds Gitea Code Injection Flaw to KEV Catalog
Code injection on a self-hosted Git server meets BOD 26-04's "total control" threshold: patching isn't optional for agencies, and contractors running Gitea face the same risk.
CISA added CVE-2026-60004, a Gitea code injection vulnerability, to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The addition triggers BOD 26-04 remediation requirements for FCEB agencies: because code injection on a Git server grants total control of the asset post-exploitation, agencies must prioritize patching and investigate whether threat actors compromised systems before the fix was applied. Gitea is widely deployed as a self-hosted Git service across government and contractor environments. This one lands in places where source code and CI/CD pipelines are the prize.