PatchSiren cyber security CVE debrief
CVE-2026-62960 git-for-windows CVE debrief
CVE-2026-62960 debrief: Git for Windows vulnerability allows malicious remote Git server to expose NTLM authentication material. Affected product deployments should be reviewed for exposure, and owners should assess and update to version 2.55.0.windows.4 or later. This high-severity vulnerability enables an attacker to initiate an outbound SMB connection, potentially exposing NTLM authentication material. The vulnerability is fixed in Git for Windows version 2.55.0.windows.4, and users should update to this version or later to mitigate the vulnerability.
- Vendor
- git-for-windows
- Product
- git
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-09-25
Who should care
Git for Windows users, particularly those using versions prior to 2.55.0.windows.4, should assess exposure and update to the latest version. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed to ensure proper mitigation and remediation.
Why it matters
CVE-2026-62960 is a high-severity vulnerability in Git for Windows that allows a malicious remote Git server to expose NTLM authentication material. Git for Windows users should update to version 2.55.0.windows.4 or later to mitigate this vulnerability.
- Potential exposure of NTLM authentication material to attacker-controlled hosts
- Possible unauthorized access to sensitive information
- Required verification of affected systems and user authentication material
- Necessity to update Git for Windows to version 2.55.0.windows.4 or later
Technical summary
A malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-HTTP(S) values are treated as local filesystem paths, and file URI prefixes are removed, so a bare UNC path or file URI targeting an attacker-controlled share causes Windows to initiate an outbound SMB connection.
Defensive priority
High priority for Git for Windows users to update to version 2.55.0.windows.4
Recommended defensive actions
- Update Git for Windows to version 2.55.0.windows.4 or later
- Review and restrict access to Git repositories
- Monitor for suspicious activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, which is fixed in Git for Windows version 2.55.0.windows.4. The vulnerability allows a malicious remote Git server to advertise a bundle URI that can cause Windows to initiate an outbound SMB connection, potentially exposing NTLM authentication material. Evidence of exposure should be verified by reviewing system logs and authentication material.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-62960 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-62960
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-62960 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62960
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/git-for-windows/git/commit/a93524749d7806870fd2b4b00a3812da1d6e5f4a
-
Source reference
Unverified legacy reference
URL: https://github.com/git-for-windows/git/releases/tag/v2.55.0.windows.4
-
Source reference
Unverified legacy reference
URL: https://github.com/git-for-windows/git/security/advisories/GHSA-xrpg-8j9v-v282
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.