Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
2026-04-28T19:24:17Z•e2ee1954c205bb7141aa6327cac0cd36faaeca8140ed9545a51c7b2436c50fe1
active-exploitationbitwardencheckmarxcisa-kevcommand-injectionfirestartergit-pushgithubglasswormhuggingfaceleRobotlmdeploylofystealerransomware-wiperremote code executionssrfsupply-chainvect-2.0windows-shell
What happened
A The Hacker News roundup highlights multiple high-impact security incidents and vulnerabilities: a critical GitHub command-injection RCE (CVE-2026-3854, CVSS 8.7) exploitable with a single git push; an unauthenticated RCE in Hugging Face LeRobot (CVE-2026-25874, CVSS 9.3); a Windows Shell flaw (CVE-2026-32202) confirmed as actively exploited; LMDeploy SSRF (CVE-2026-33626) seen in the wild within 13 hours of disclosure; and CISA additions to the KEV list including CVE-2024-57726. The feed also reports supply-chain and malware activity: Checkmarx repository data posted to the dark web, Bitward
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- e2ee1954c205bb7141aa6327cac0cd36faaeca8140ed9545a51c7b2436c50fe1
- Enrichment time
- 2026-04-28T19:24:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.