CVE-2026-60004: Gitea Code Injection Vulnerability
CVE-2026-60004 affects Gitea Gitea and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-25.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
CVE-2026-60004 affects Gitea Gitea and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-25.
CVE-2019-1068 affects Microsoft SQL Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-26.
CVE-2026-8452 affects Citrix NetScaler ADC and NetScaler Gateway and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-26.
CVE-2022-0995 affects Linux Kernel and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-26.
CVE-2015-5287 affects Red Hat Automatic Bug Reporting Tool and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-26.
CVE-2015-3246 affects Red Hat Libuser and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-26.
CVE-2021-23758 affects Ajax.NET Professional Ajax.NET Professional and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-26.
CVE-2026-66384 affects JFrog Artifactory and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-27.
CVE-2026-53362 affects Linux Kernel and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-27.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.