2026-09-17

This week

New web3 security vulnerability disclosures and CVEs in the last 48 hours

# RESEARCH: New Web3 Security Vulnerability Disclosures and CVEs (Last 48 Hours)

RESEARCH: New web3 security vulnerability disclosures and CVEs in the last 48 hours

# RESEARCH: New Web3 Security Vulnerability Disclosures and CVEs (Last 48 Hours)

Summary

In the past two days, several critical vulnerabilities affecting key Web3 infrastructure components have been disclosed. The primary sources are GitHub advisories detailing multiple security flaws in Git-related tools (GitHub Desktop, Git Credential Manager, Git LFS) that could lead to unauthorized credential leakage and privilege escalation. Additionally, CISA has added newly exploited vulnerabilities to its catalog, highlighting ongoing threats across various protocols. These disclosures underscore the importance of prompt patching and responsible disclosure practices within Web3 development communities.

Key Developments

Sources