CISA's exploited-bug list flags Gitea flaw — but the fetched reporting is about Ray, not Gitea
The estate's trigger named a Gitea vulnerability, CVE-2026-60004, as newly added to CISA's Known Exploited Vulnerabilities catalogue — but the material pulled to report it covers a different bug entirely, so here's what can and can't be confirmed.
Wayne's ledger flagged a specific alert: CVE-2026-60004, a vulnerability in Gitea — the self-hosted Git service used by developers to manage code repositories — had landed on CISA's Known Exploited Vulnerabilities (KEV) catalogue. That listing, by itself, means the US Cybersecurity and Infrastructure Security Agency believes the flaw is being actively exploited in the wild. That is the whole of what the trigger tells us.
The reporting material gathered to back that trigger, however, does not mention Gitea, and does not mention CVE-2026-60004. Both sources supplied are about a separate KEV entry: CVE-2025-62593, a code-injection flaw in Ray, the open-source AI framework maintained by Anyscale, added to the catalogue on 17 August with a three-day patch deadline for federal agencies, according to [1]. The second source, [2], covers a related but distinct development — CISA's new Binding Operational Directive 26-04, which changes how federal agencies are meant to prioritise patching generally, including KEV-listed bugs.
Nothing in either source establishes any fact about the Gitea vulnerability itself: not its severity, not how it can be exploited, not which Gitea versions are affected, not whether a patch exists, and not what CISA's remediation deadline is for it. Wayne should not take anything below as reporting on the Gitea flaw — it is reporting on the KEV process in general, surfaced because the same catalogue and the same federal deadline mechanism apply.
What the material does establish, reliably, is how CISA's KEV system works and why a listing matters. Under BOD 26-04 — which supersedes the older BOD 22-01 and BOD 19-02 — federal civilian agencies must assess vulnerabilities against asset exposure, KEV status, exploit automation and post-exploitation impact, according to [2]. Acting CISA Director Nick Andersen is quoted saying the aim is to let agencies "focus their efforts on the areas of highest risk" rather than treat every listed bug identically, according to [2]. The directive also tells agencies to check for prior compromise before assuming a patch alone fixes things, since patching does not evict an attacker already inside, according to [2].
The Ray case in [1] is a useful illustration of what a KEV addition typically signals: a fix already available (Ray 2.52.0), a short mandated federal patch window (20 August, three days from listing), and a history — the 2024 "ShadowRay" campaign documented by Oligo Security, which compromised over 230,000 exposed Ray servers for cryptomining and data theft — of what happens to this class of software when left exposed, according to [1].
Given the mismatch between trigger and material, the honest position is: a Gitea flaw is now officially confirmed as actively exploited, per the CISA catalogue naming convention in the trigger itself, but every operational detail — affected versions, patch availability, attack vector, federal deadline — is unconfirmed pending source material that actually addresses CVE-2026-60004.
What to watch next: whether CISA's own KEV entry for CVE-2026-60004 turns up with specifics — affected Gitea versions, a fixed release, and the binding federal remediation date — so this can be properly reported rather than inferred from an unrelated Ray disclosure.
More from this edition
- A US military plane landed in Moscow with no public explanation offered by the Kremlin or Trump, per its Ukraine-Russia war live coverage
- A teenager was stabbed to death at a London council building, corroborating the BBC's report of a fatal stabbing at Brent Civic Centre
- Young people leaving care are four times more likely to die sooner, corroborating the BBC's care-leaver mortality report
- Five new arrests in the A66 crash investigation, including a man accused of making threats to kill
- Canada announced $20bn in retaliatory tariffs on US goods, with officials saying 'we're not going to bend'
- GOV.UK announces Homes England and government have confirmed strategic partners to help deliver an increase in social and affordable housing across…
- A tornado hit a village in southern France
- AI-generated content is flooding public bodies with complaints and requests