logo

GitHub Enterprise Server vulnerability: Find impacted assets

ID: 7d9a28e3-1756-5dfd-968f-007341ccfec2

STIX ID: report--7d9a28e3-1756-5dfd-968f-007341ccfec2

Feed Name: runZero Blog

Threat Score
75/100

Date Published: 2026-04-28

Date Updated: 2026-04-29

Author: Matthew Kienow

...
...

GitHub disclosed CVE-2026-3854, a high-severity (CVSS 8.7) remote code execution vulnerability in GitHub Enterprise Server allowing an authenticated, low-privileged user with push access to achieve arbitrary command execution via a crafted git push. Multiple GHES versions are listed as affected and GitHub provides patched versions for immediate upgrade to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.