Red Heron Gitea CVE-2026-60004 exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
An active CVE-2026-60004 exploitation wave is targeting Gitea instances across seven countries, converting public proof-of-concept code into an automated scanning framework. The activity has already driven compromises in Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka and moved beyond initial access into repository theft and credential collection. The wave raises immediate risk for internet-facing self-hosted development platforms because exposed instances can be scanned at scale and quickly turned into persistent footholds.
Related Happenings
Red Heron Gitea RCE exploitation campaign
Campaign
H score17
First: 14.09.2026 19:56
Last: 14.09.2026 19:56
Sources 1
How related:
"Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems,"
About this happening:
The Red Heron campaign rapidly weaponized CVE-2026-60004 in Gitea to compromise internet-facing instances, exposing source code, credentials, and connected infrastruct...
Red Heron Gitea RCE exploitation campaign
CampaignHow related: "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems,"
About this happening: The Red Heron campaign rapidly weaponized CVE-2026-60004 in Gitea to compromise internet-facing instances, exposing source code, credentials, and connected infrastruct...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation Wave
H score53
First: 05.09.2026 10:31
Last: 05.09.2026 10:31
Sources 1
About this happening:
PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation WaveAbout this happening: PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
Gitea diffpatch endpoint RCE (CVE-2026-60004)
Vulnerability
H score41
First: 29.07.2026 10:47
Last: 29.07.2026 10:47
Sources 1
About this happening:
CVE-2026-60004 is a critical remote code execution flaw in Gitea that lets a user with repository write access run shell commands as the Gitea service account. The...
Gitea diffpatch endpoint RCE (CVE-2026-60004)
VulnerabilityAbout this happening: CVE-2026-60004 is a critical remote code execution flaw in Gitea that lets a user with repository write access run shell commands as the Gitea service account. The...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
H score55
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch ReleaseAbout this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)
Exploitation Wave
H score89
First: 04.05.2026 11:25
Last: 04.05.2026 11:25
Sources 1
About this happening:
CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...
CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)
Exploitation WaveAbout this happening: CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...
Timeline
-
14.09.2026 19:56 2 articles · 2h ago
Red Heron weaponizes CVE-2026-60004 against internet-facing Gitea
Exploitation ObservedRed Heron began weaponizing CVE-2026-60004 against internet-facing Gitea instances, converting public proof-of-concept code into an automated Python framework called exp_enhanced.py and scanning thousands of instances across seven countries.
Show sources
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries — thehackernews.com — 14.09.2026 19:56
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries — thehackernews.com — 14.09.2026 19:56
-
14.09.2026 19:56 1 articles · 2h ago
Red Heron's Gitea campaign exposes JITTERLY, SIXZUT, and cross-border compromises
Campaign Scope UpdateRed Heron's Gitea campaign was linked to 13 organizations across six countries, with compromises in Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka, and analysis of a staging server uncovered the C++ Linux implant JITTERLY and the LD_PRELOAD rootkit SIXZUT. The activity progressed from source-code theft to credential collection, persistent access, lateral movement, and root-level access to a three-node Proxmox cluster.
Show sources
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries — thehackernews.com — 14.09.2026 19:56