Critical
🔴 Actively Exploited
CVE-2026-3854
GitHub Enterprise
CVE-2026-3854 — GitHub Enterprise Server Remote Code Execution via Single Git Push (CVSS 9.8)
Affected Product
GitHub Enterprise Server
Exploit Status
In-the-Wild PoC
Attack Vector
Network / Unauth
Patch Available
Yes — v3.15.1
First Disclosed
May 22, 2026
▶ Recommended Action
1. Update GitHub Enterprise Server to v3.15.1 immediately.
2. Restrict git push to authenticated users — enforce SSH key or token auth.
3. Review audit logs for anomalous push events from unexpected IPs.
Critical
🔴 Actively Exploited
CVE-2026-6973
Ivanti EPMM
CVE-2026-6973 — Ivanti Endpoint Manager Mobile Authentication Bypass Leads to RCE (CVSS 9.4) — CISA KEV Added
Affected Product
Ivanti EPMM
Attack Vector
Network / No Auth
Patch Available
Yes — May Advisory
Inventory Match
AirWatch / MDM
▶ Recommended Action
1. Apply Ivanti May 2026 patches immediately — CISA KEV listed.
2. Restrict EPMM admin portal to trusted IPs if patching delayed.
3. Review MDM enrollment logs for unauthorized devices since May 1.
High
CVE-2026-3902
Cisco IOS-XE
Patch Available
CVE-2026-3902 — Cisco IOS-XE Web UI Privilege Escalation — Unauthenticated Admin Access (CVSS 8.8)
Affected Product
Cisco IOS-XE Web UI
Exploit Status
PoC Published
Inventory Match
Cisco networking
Patch Available
Yes — Cisco PSIRT
▶ Recommended Action
1. Disable HTTP/HTTPS server on affected IOS-XE devices if not operationally required.
2. Apply Cisco PSIRT patch — restrict Web UI to management VLANs only.
CVE Quick View — Today
Critical & High
CVE-2026-3854GitHub Enterprise9.8
CVE-2026-6973Ivanti EPMM9.4
CVE-2026-3902Cisco IOS-XE8.8
CVE-2026-4411VMware vCenter8.2
CVE-2026-2951Windows Server7.8
Vuln Summary — Today
Top vendorGitHub / Cisco
CISA KEV adds1 new today
Actively exploited4 of 7 CVEs
Patches available7 of 7
Top CVSS9.8 Critical
🛡 Executive Summary
Today's report identifies 7 new CVEs. Two critical vulnerabilities in GitHub Enterprise and Ivanti EPMM are actively exploited. Cisco IOS-XE and VMware vCenter require patches within 72 hours.