Pull to refresh
Logo
Forgejo patches critical RCE affecting versions through 16.0.3

Forgejo patches critical RCE affecting versions through 16.0.3

New Capabilities

Third critical 16.x security fix since July, after August cryptominer attacks

Today: Forgejo 16.0.4 fixes critical RCE

Overview

Updated 1 hour ago

Forgejo released version 16.0.4 on September 10 to close a critical remote code execution vulnerability affecting every version through 16.0.3. The news reached Hacker News the same day.

It is the third 16.x patch release to carry security fixes since mid-July. The stretch includes CVE-2026-60004, a patch-application bug rated 9.8, which attackers exploited in August to plant cryptominers and steal credentials.

Why it matters

Forgejo instances running anything older than 16.0.4 are remotely exploitable, and operators on out-of-support releases have no patch path.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

9.8
CVSS severity of CVE-2026-60004
The diffpatch-to-git-hook RCE exploited in August.
94
Attacker accounts in one August compromise
Each held one repository planted with a git hook.
3
Security patch releases in the 16.x line since July
16.0.2, 16.0.3 and 16.0.4 each carried security fixes.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

Play

Exploring all sides of a story is often best achieved with Play.

Most of these play right now — no account needed. Sign up to save scores, keep a streak, and unlock Debate and Predict. Log in Sign Up
Predict 3 ways this could play out. Back the one you believe — contrarian picks score more when a scenario has a resolution date. Log in to play

People Involved

Organizations Involved

Timeline

July 2026 September 2026

10 events Latest: Today
Tap a bar to jump to that date
  1. Forgejo 16.0.4 fixes critical RCE

    Today Security

    Forgejo releases 16.0.4 to patch a critical RCE affecting versions through 16.0.3; Hacker News reports the same day.

  2. Postmortem published

    Statement

    Operator publishes a detailed postmortem of the Forgejo compromise.

  3. Service restored

    Response

    Operator scopes the incident and restores Forgejo service the same day.

  4. Compromise detected

    Incident

    Compromise detected: 94 attacker accounts, exfiltrated credentials, cryptominer running.

  5. CISA adds CVE to KEV catalog

    Government

    CISA adds CVE-2026-60004 to its Known Exploited Vulnerabilities catalog.

  6. Forgejo releases v15.0.7 and v16.0.3

    Security

    Forgejo releases v15.0.7 and v16.0.3 with multiple security fixes.

  7. Homelab instance compromised

    Incident

    Homelab Forgejo v13 instance compromised; cryptominer installed.

  8. Automated scanning detected

    Incident

    Automated scanning for the diffpatch RCE detected in the wild.

  9. First attacker activity recorded

    Incident

    First attacker activity exploiting CVE-2026-60004 recorded on a Forgejo instance.

  10. Forgejo v16 patches stored XSS

    Security

    Forgejo v16 security patches fix stored XSS and access control bugs.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

March-September 2017

Equifax and Apache Struts (2017)

Apache patched a critical RCE in its Struts framework (CVE-2017-5638) in March 2017. Equifax had not applied it; attackers exploited the flaw in May, stealing data on 147 million people. The breach was disclosed in September.

Then

Equifax reached a settlement exceeding $1 billion and replaced its leadership.

Now

The case became the standard example of a known, patchable RCE left unpatched in production.

Why this matters now

The Forgejo postmortem told the same story: the fix was out for a week while the instance ran a version six months past end of life.

October-November 2021

GitLab CVE-2021-22205 (2021)

A critical RCE in GitLab CE/EE, a self-hosted Git platform, was exploited in the wild. Attackers installed cryptominers on unpatched instances before GitLab issued urgent fixes.

Then

GitLab pushed emergency patches and CISA added the CVE to its catalog.

Now

Self-hosted Git forges became a recognized target class for cryptominer deployment.

Why this matters now

The same target class, the same payload, and the same failure mode: unpatched self-hosted instances.

December 2021

Log4Shell (2021)

A critical RCE in Apache Log4j, a logging library embedded in hundreds of thousands of applications, forced every downstream project to scramble. Many inherited the flaw without knowing they ran it.

Then

Organizations spent months inventorying and patching affected software.

Now

It demonstrated how a single upstream bug ripples through every fork and dependency.

Why this matters now

Forgejo inherited CVE-2026-60004 from Gitea, its upstream fork source. Downstream projects carry upstream bugs until they ship their own patches.

Sources

(8)