Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push

2026-04-28T19:24:17Ze2ee1954c205bb7141aa6327cac0cd36faaeca8140ed9545a51c7b2436c50fe1
active-exploitationbitwardencheckmarxcisa-kevcommand-injectionfirestartergit-pushgithubglasswormhuggingfaceleRobotlmdeploylofystealerransomware-wiperremote code executionssrfsupply-chainvect-2.0windows-shell

What happened

A The Hacker News roundup highlights multiple high-impact security incidents and vulnerabilities: a critical GitHub command-injection RCE (CVE-2026-3854, CVSS 8.7) exploitable with a single git push; an unauthenticated RCE in Hugging Face LeRobot (CVE-2026-25874, CVSS 9.3); a Windows Shell flaw (CVE-2026-32202) confirmed as actively exploited; LMDeploy SSRF (CVE-2026-33626) seen in the wild within 13 hours of disclosure; and CISA additions to the KEV list including CVE-2024-57726. The feed also reports supply-chain and malware activity: Checkmarx repository data posted to the dark web, Bitward

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
e2ee1954c205bb7141aa6327cac0cd36faaeca8140ed9545a51c7b2436c50fe1
Enrichment time
2026-04-28T19:24:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.