CISA Adds One Known Exploited Vulnerability to Catalog

Summary

CISA has added CVE-2026-60004, a Gitea code injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This addition reinforces the importance of CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize the remediation of such high-risk vulnerabilities on publicly exposed assets.

IFF Assessment

FOE

The addition of a known exploited vulnerability to CISA's catalog indicates active threats that defenders must address, posing a risk.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: August 28, 2026. Known ransomware use: Unknown.

Defender Context

Organizations, particularly federal agencies, must prioritize patching CVE-2026-60004 as it is now officially recognized as actively exploited. This highlights the ongoing threat posed by code injection vulnerabilities and the importance of maintaining a robust vulnerability management program to track and remediate high-risk issues promptly.

Read Full Story →