Skip to content
ThreatCluster

Critical SSRF Vulnerability in GitHub Enterprise Server (CVE-2026-77987)

First seen 24 Sep 2026, 11:27 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 24, 2026 at 12:55 UTC
  • CVE-2026-77987 affects GitHub Enterprise Server versions 3.17 to 3.22.
  • The vulnerability allows SSRF attacks via the notebook viewer, with a CVSS score of 9.3.
  • No evidence of exploitation in the wild has been reported, but immediate patching is recommended.

CVE-2026-77987 is a critical server-side request forgery (SSRF) vulnerability affecting GitHub Enterprise Server versions 3.17 to 3.22. This flaw allows attackers to exploit the notebook viewer by supplying a URL with an explicit port, potentially accessing internal services. The vulnerability has a CVSS v4.0 score of 9.3, indicating high impact on confidentiality, integrity, and availability. Exploitation requires network access and can be unauthenticated in certain configurations. Currently, there is no public evidence of exploitation in the wild. The Centre for Cybersecurity Belgium recommends immediate patching and enhanced monitoring for affected systems. Organizations are advised to report any suspicious activity and ensure swift incident response. Patching does not remediate any historic compromises that may have occurred prior to updates.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-22
CVE-2026-77987 published
GitHub disclosed a critical SSRF vulnerability affecting versions 3.17 through 3.22 of GitHub Enterprise Server.
Ccb.Belgium.Be
2026-09-24
Advisory issued for CVE-2026-77987
The Centre for Cybersecurity Belgium issued a warning and recommended immediate patching for affected GitHub Enterprise Server instances.
Ccb.Belgium.Be

More articles in this cluster (3)

Following this threat?

Track CVE-2026-77987 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed