1.
wiz.io | vulnerability | | original ↗ | #rce | #vulnerability-research | #github | #enterprise-security
CVE-2026-3854: a Wiz-discovered injection flaw let any authenticated user get RCE on GitHub's shared storage nodes via one git push; fixed within hours, but 88% of GHES instances stayed vulnerable.
Skip to content