Skip to content

// #cve-2026-3854

1 article

💻 AppSec

GitHub Enterprise Server CVE-2026-3854 — Critical RCE via Single Git Push, No Authentication Required

CVE-2026-3854, a critical-severity remote code execution vulnerability in GitHub Enterprise Server, allows an attacker to execute arbitrary code on the server with a single specially crafted Git push, requiring no authentication. Any internet-exposed or internally-accessible GHES instance is vulnerable. GitHub has released hotfixes across all supported branches; apply immediately.

#github-enterprise +6