GitHub Enterprise Server Security Update Advisory (CVE-2026-3854)

GitHub Enterprise Server Security Update Advisory (CVE-2026-3854)

Overview


A security update has been released for CVE-2026-3854, a remote code execution vulnerability in GitHub Enterprise Server. users of the affected products should update to the latest version.

Affected products


  • GitHub Enterprise Server 3.14.25 and earlier.
  • GitHub Enterprise Server 3.15.20 and earlier.
  • GitHub Enterprise Server 3.16.16 and earlier.
  • GitHub Enterprise Server 3.17.13 and earlier.
  • GitHub Enterprise Server 3.18.7 or earlier.
  • GitHub Enterprise Server 3.19.4 or earlier.

Resolved vulnerabilities


  • CVE-2026-3854: Remote code execution vulnerability in GitHub Enterprise Server, which could allow threat actors to remotely execute code.

What to do


vulnerability patches have been made available in the latest update. you should follow the instructions on the reference site to update to the latest version of the Vulnerability Patch.