logo

Critical RCE Vulnerability in GitHub Affects Millions of Repositories

ID: 3062a89d-605d-5403-bb28-b7e49552c1d5

STIX ID: report--3062a89d-605d-5403-bb28-b7e49552c1d5

Feed Name: ThreatCluster

Threat Score
76/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

...
...

A critical RCE vulnerability (CVE-2026-3854) in GitHub's internal git infrastructure can be exploited via a single git push by any authenticated user, potentially allowing full server compromise and exposure of private repositories and secrets. GitHub mitigated github.com within six hours and released patches for GitHub Enterprise Server, but the report states 88% of Enterprise instances remain vulnerable; administrators are urged to upgrade to version 3.19.3 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.