CVE-2026-3854 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
11
occurrences
First Seen
April 28, 2026
Last Seen
April 29, 2026

CVE-2026-3854 is a vulnerability tracked across 1 threat cluster and 11 intelligence report mentions on ThreatCluster. First observed April 28, 2026; most recent activity April 29, 2026.

Related Threat Clusters

  • GitHub Patches Critical RCE Vulnerability CVE-2026-3854

    A critical remote code execution vulnerability, tracked as CVE-2026-3854, was discovered in GitHub's internal git infrastructure, allowing authenticated users to execute arbitrary commands via a crafted git push…

    49 articles · Updated April 28, 2026

Recent Intelligence Reports

  • Wiz hands GitHub AI-aided bug report that isn't total slop — Theregister · April 29, 2026
  • GitHub Fixes RCE Flaw that Gave Access to Millions of Private Repos — Ground.News · April 29, 2026
  • GitHub: Woah, a genuinely helpful AI-assisted bug report that isn't total slop. Here, Wiz, take this wad of cash — Theregister · April 29, 2026
  • CVE-2026-3854 — nvd.nist.gov · April 29, 2026
  • GitHub fixes RCE flaw that gave access to millions of private repos — Bleepingcomputer · April 29, 2026
  • Critical GitHub RCE bug exposed millions of repositories — Csoonline · April 29, 2026
  • GitHub Fixes Critical RCE Bug CVE-2026 — Thecyberexpress · April 29, 2026
  • GitHub.com and Enterprise Server Vulnerability Allows Remote Code Execution — Gbhackers · April 29, 2026

CVSS v3.1 Breakdown