GitHub fixes RCE flaw that gave access to millions of private repos
ID: 176749dc-0270-587e-9372-b54929862969
STIX ID: report--176749dc-0270-587e-9372-b54929862969
Feed Name: Bleeping Computer
Threat Score
A critical RCE vulnerability (CVE-2026-3854) in GitHub's git push handling could let an attacker with push access execute arbitrary code and access millions of private and public repositories; GitHub patched GitHub.com rapidly and published updates for GitHub Enterprise Server, but many GHES instances remained vulnerable and administrators were urged to upgrade immediately. Forensic telemetry indicated no evidence of exploitation prior to the responsible researchers' testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
