HIGH
git-for-windows
CVE published 2026-08-21
CVE-2026-62960
Git for Windows is vulnerable to a malicious remote Git server attack that can cause Windows to initiate an outbound SMB connection, potentially exposing NTLM authentication material. This issue is fixed in version 2.55.0.windows.4. Users should be aware of the vulnerability and take steps to mitigate it, including updating to the latest version and reviewing access to Git repositories.