GitHub released security updates for GitHub Enterprise Server (GHES) that remediate CVE-2026-77987, a critical server-side request forgery (SSRF)-style vulnerability in the notebook viewer. A network-accessible attacker could use a viewer URL containing an explicit port to probe co-located internal services; response timing could disclose appliance secrets and potentially enable remote code execution. The updates also fix CVE-2026-77912, a high-severity stored cross-site scripting vulnerability through which an authenticated attacker could inject arbitrary HTML attributes using crafted Markdown, execute scripts in other users’ browsers, steal data, perform victim-authorized actions, or self-propagate.
Affected GHES installations should be upgraded to the applicable fixed version: 3.17.21, 3.18.15, 3.19.12, 3.20.8, 3.21.6, or 3.22.1. The releases additionally correct an authorization issue that could let a party holding package-upload identifiers corrupt an in-progress GitHub Packages upload, alongside reliability issues affecting Dependabot, Redis recovery, backup and restore, and resource consumption. Administrators should reapply custom firewall rules after upgrading because the upgrade process removes them.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
GitHub released GHES 3.22.1 and published a security advisory covering affected 3.17 through 3.22 release branches. The updates fixed critical SSRF-style flaw CVE-2026-77987, high-severity stored XSS CVE-2026-77912, and a GitHub Packages upload authorization flaw; fixed releases included 3.17.21, 3.18.15, 3.19.12, 3.20.8, 3.21.6, and 3.22.1.
GitHub released GitHub Enterprise Server 3.22.0, adding a replication controller, CodeQL 2.25.6 with incremental pull-request analysis, Dependabot alerts for known malicious npm packages, and additional hook-networking restrictions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.