Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)

Summary

CVE-2026-3854: a Wiz-discovered injection flaw let any authenticated user get RCE on GitHub's shared storage nodes via one git push; fixed within hours, but 88% of GHES instances stayed vulnerable.
Published
Collected

original ↗

Related coverage

back