CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1302

As cited

Copy frozen at (site build).

vulnerabilities

Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)

A critical remote code execution vulnerability (CVE-2026-3854) was discovered in GitHub's internal git infrastructure by Wiz Research, affecting both GitHub.com and GitHub Enterprise Server. The flaw enables attackers to execute arbitrary code on affected systems.

Why it matters: GitHub users and enterprise customers running GitHub Enterprise Server must assess whether this vulnerability has been exploited and apply available patches immediately, as remote code execution represents direct compromise of code repositories and deployment infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)

A critical remote code execution vulnerability (CVE-2026-3854) was discovered in GitHub's internal git infrastructure by Wiz Research, affecting both GitHub.com and GitHub Enterprise Server. The flaw enables attackers to execute arbitrary code on affected systems.

Why it matters: GitHub users and enterprise customers running GitHub Enterprise Server must assess whether this vulnerability has been exploited and apply available patches immediately, as remote code execution represents direct compromise of code repositories and deployment infrastructure.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary