TGViewer
CatOps CatOps @catops · 5.08K subscribers
Post #2892 1.57K
If you're hosting GitHub Enterprise Server, you need to update to address a recently discovered CVE.

What's interesting about this CVE is that it is a legit CVE that was discovered with AI. As WIZ researchers put it in the related article

Notably, this is one of the first critical vulnerabilities discovered in closed-source binaries using AI, highlighting a shift in how these flaws are identified.


Security notice from GitHub.

Fixed versions:

- GitHub Enterprise Server 3.14.25 or later
- GitHub Enterprise Server 3.15.20 or later
- GitHub Enterprise Server 3.16.16 or later
- GitHub Enterprise Server 3.17.13 or later
- GitHub Enterprise Server 3.18.7 or later
- GitHub Enterprise Server 3.19.4 or later
- GitHub Enterprise Server 3.20.0 or later

P.S. These news came from our chat (in Ukrainian).

#security #github
wiz.io GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.
More from @catops
  1. Sep 29, 2026A Cybersecurity books bundle by O’Reilly on Humble Bundle. The bundle is fresh and is stil…
  2. Sep 28, 2026​​For today’s Donations Monday, I’d like to remind you about a fundraiser for a pickup tru…
  3. Sep 26, 2026Here’s Datadog’s take on the increased load on CI. In this article they explain how their…
  4. Sep 25, 2026A new chapter of the CatOps Digest is here! https://newsletter.catops.dev/p/catops-digest-…
  5. Sep 24, 2026Shopify wrote an article on them moving from React Native to the native code for their mob…
  6. Sep 23, 2026A bunch of practice exams on Humble Bundle, if you're into this type of thing. This offer…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →