<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[GitHub Patches Critical RCE Vulnerability in GitHub.com and GitHub Enterprise Server]]></title><description><![CDATA[<p>GitHub Patches Critical RCE Vulnerability in GitHub.com and GitHub Enterprise Server</p><p>GitHub patched a critical RCE vulnerability (CVE-2026-3854) in its internal git infrastructure that allowed authenticated users to compromise backend servers and access millions of repositories.</p><p>**If you run GitHub Enterprise Server (version 3.19.1 or earlier), upgrade immediately to a patched version (3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.8, 3.19.4, 3.20.0, or later) since nearly 90% of instances are still unpatched. Also check your audit logs at `/var/log/github-audit.log` for push operations with unusual special characters in option values to spot any exploitation attempts; if you use GitHub.com or GitHub Enterprise Cloud, no action is needed since GitHub already fixed it.**<br /><a href="https://infosec.exchange/tags/cybersecurity" rel="tag">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/advisory" rel="tag">#<span>advisory</span></a> <a href="https://infosec.exchange/tags/vulnerability" rel="tag">#<span>vulnerability</span></a><br /><a href="https://beyondmachines.net/event_details/github-patches-critical-rce-vulnerability-in-github-com-and-github-enterprise-server-r-x-e-8-5/gD2P6Ple2L" rel="nofollow noopener"><span>https://</span><span>beyondmachines.net/event_detai</span><span>ls/github-patches-critical-rce-vulnerability-in-github-com-and-github-enterprise-server-r-x-e-8-5/gD2P6Ple2L</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/9c6c4be7-31c5-4c32-be25-9989f3925ea9/github-patches-critical-rce-vulnerability-in-github.com-and-github-enterprise-server</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 04:25:43 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/9c6c4be7-31c5-4c32-be25-9989f3925ea9.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 29 Apr 2026 15:01:43 GMT</pubDate><ttl>60</ttl></channel></rss>