A critical vulnerability in the ServiceNow AI Platform, identified as CVE-2026-6875, is being actively exploited by attackers. This pre-authentication code injection flaw allows unauthenticated users to escape the platform's script sandbox and execute arbitrary code on targeted instances. Researchers from Searchlight Cyber discovered this vulnerability and reported it to ServiceNow in early April 2026. The exploitation of this vulnerability poses significant risks to organizations using the ServiceNow AI Platform, as it could lead to unauthorized access and control over sensitive workflows and data. Companies are urged to take immediate action to safeguard their systems against potential attacks.
Articles tagged "CVE"
Found 574 articles
SonicWall discovered that two zero-day vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, were exploited by a threat actor known as UTA0533. These vulnerabilities were actively used to deliver custom malware over several weeks before a patch was released. Organizations using affected SonicWall products need to be particularly vigilant, as the malware has already been deployed in the wild. This situation emphasizes the importance of timely patch management and monitoring for unusual activity, given that attackers can exploit such vulnerabilities to gain unauthorized access to systems. Companies should prioritize updating their security infrastructure to mitigate the risk posed by these exploits.
Security Affairs
F5 has patched a serious vulnerability in NGINX, identified as CVE-2026-42533, which has a CVSS score of 9.2, indicating it is highly critical. This flaw allows unauthenticated attackers to exploit a heap buffer overflow by sending specially crafted HTTP requests, potentially leading to server crashes or remote code execution. This vulnerability affects NGINX servers widely used for hosting websites and applications, making it a significant concern for organizations relying on this technology. F5's quick response to release patches is crucial to mitigate the risks associated with this vulnerability, as it could lead to severe disruptions or data breaches if left unaddressed.
A serious vulnerability (CVE-2026-6875) in the ServiceNow AI Platform is currently being exploited by attackers, according to threat intelligence firm Defused. This flaw allows unauthorized code execution, which can lead to significant security breaches for organizations using the platform. Companies that rely on ServiceNow for their IT service management need to be particularly vigilant, as the exploitation of this vulnerability could compromise sensitive data and disrupt services. The urgency of the situation is heightened by the fact that attackers are already taking advantage of this weakness, making it essential for affected organizations to act quickly to protect their systems.
A newly discovered vulnerability in 7-Zip, identified as CVE-2026-14266, could allow attackers to execute arbitrary code on a user's machine when they open a specially crafted XZ archive. This security flaw stems from a heap-based buffer overflow that occurs during the processing of XZ chunked data. The issue was detailed by Trend Micro's Zero Day Initiative on July 15, but a fix was already released on June 25 with version 26.02 of 7-Zip. Users of 7-Zip should update to this latest version to protect themselves from potential exploitation. The vulnerability poses a serious risk, as it can run code in the context of the current process, making it a significant concern for anyone using the software.
The Hacker News
F5 has released important updates to address a critical vulnerability in NGINX, identified as CVE-2026-42533. This flaw allows attackers to send specially crafted HTTP requests that can cause a heap buffer overflow in the NGINX worker process. As a result, this vulnerability could lead to the crashing or restarting of the worker, effectively denying service to legitimate users. The issue affects versions of NGINX prior to 1.30.4 and 1.31.3, as well as NGINX Plus versions before 37.0.3.1. Users running these versions should upgrade immediately to protect their systems from potential exploitation.
Security Affairs
Recent discoveries have revealed serious vulnerabilities in WordPress, specifically two flaws tracked as CVE-2026-63030 and CVE-2026-60137. These vulnerabilities, known as wp2shell, can be exploited by attackers to execute code remotely without needing authentication. This means that anyone with these vulnerabilities can potentially take control of a WordPress site, particularly those running default configurations. The availability of public proof-of-concept exploits raises the urgency for website owners to address these flaws promptly, as they are now at greater risk of being targeted by malicious actors. It’s critical for users to be aware of these vulnerabilities and take immediate action to secure their sites.
WordPress has released a security update, version 7.0.2, to address two significant vulnerabilities that pose risks to users. The first vulnerability, identified as CVE-2026-60137, is a SQL injection issue that could allow attackers to manipulate databases. The second, also CVE-2026-60137, relates to a REST API batch-route confusion that could lead to remote code execution, potentially giving attackers full control over affected systems. The vulnerabilities affect WordPress version 6.9 and earlier. Users are strongly advised to update their installations immediately to mitigate the risks associated with these security flaws.
A recently discovered vulnerability in OpenSSL, dubbed the HollowByte flaw, can cause unpatched servers to reserve up to 131 KB of memory for a tiny 11-byte TLS request that never arrives. This issue can lead to a denial-of-service condition, where the server's memory is tied up until the process is restarted. The problem was identified by Okta's Red Team, which reported it without a CVE or formal advisory. OpenSSL issued a fix for this vulnerability in June, but the lack of documentation means many users may remain unaware of the risk. As a result, organizations running affected OpenSSL versions should ensure they apply the update to avoid potential service disruptions.
Security Affairs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included new vulnerabilities in its Known Exploited Vulnerabilities catalog, specifically targeting the KNX Protocol Connection Authorization Option 1 from the KNX Association and various flaws related to Oracle products. This update is crucial as it indicates that these vulnerabilities could be actively exploited by attackers, posing risks to organizations using affected systems. The inclusion of these vulnerabilities serves as a warning to IT departments and security teams to prioritize patching and mitigation efforts. Notably, CISA also added vulnerabilities from SonicWall and Microsoft to the catalog, emphasizing the ongoing need for vigilance in cybersecurity practices. Companies should review their systems and apply necessary updates to safeguard against potential attacks.
The Hacker News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft SharePoint Server to its list of Known Exploited Vulnerabilities. This flaw, identified as CVE-2026-58644, has a high severity score of 9.8, indicating that it poses a significant risk. Federal Civilian Executive Branch agencies are mandated to implement necessary patches by July 19, 2026. The vulnerability involves a deserialization issue that could allow attackers to execute remote code on affected systems, making it crucial for organizations using SharePoint to take immediate action. By addressing this vulnerability, agencies can help prevent potential exploitation by malicious actors.
All CISA Advisories
Rockwell Automation has identified several vulnerabilities in its CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix products that could allow attackers to cause a denial-of-service (DoS) condition. The affected versions include various models of CompactLogix and ControlLogix controllers, specifically those running versions V35.015 or lower for the 5370 and 5570 series, and V34.012 or V35.011 for the 5380, 5480, and 5580 series. If exploited, these vulnerabilities could lead to the devices entering a non-recoverable fault state, disrupting operations in critical manufacturing sectors. Users are urged to update their systems to the latest versions to mitigate these risks, as the vulnerabilities have a high severity rating (CVSS score of 8.6).
Siemens has identified multiple vulnerabilities in its SICAM 8 product line, which could lead to denial of service and other security risks. The affected products include the CPCI85 Central Processing/Communication and SICORE Base system versions prior to 26.20.0. These vulnerabilities could allow attackers to disrupt services, install malicious firmware, or gain unauthorized access to critical system functions. Siemens has released updates for the affected products and strongly advises users to upgrade to the latest versions to mitigate these risks. This is particularly important for operators in critical infrastructure sectors like energy and manufacturing, where such vulnerabilities could have serious implications.
Rockwell Automation has reported a vulnerability in its Flex 5000 Adapter, specifically version 6.011, that could lead to a denial-of-service (DoS) condition. This issue arises from improper handling of specific CIP packets, which can cause the adapter to become unresponsive, necessitating a power cycle to restore functionality. The vulnerability is classified as CVE-2026-12659 and has a CVSS score of 7.5, indicating a high severity level. Users are advised to upgrade to version 6.012 to mitigate this risk. For those unable to update, Rockwell Automation recommends following its security best practices to safeguard their systems. This vulnerability is particularly concerning for sectors involved in critical manufacturing and information technology, affecting organizations globally.
A vulnerability in SALTO ProAccess Space has been identified, allowing authenticated attackers to escalate their privileges and access areas outside their designated partitions. This flaw affects versions below 6.13 and requires valid operator credentials and the partition feature to be enabled. Organizations using this system should urgently upgrade to version 6.13 to mitigate the risk. The vulnerability, designated as CVE-2026-11889, poses a significant threat as it could allow unauthorized access to spaces managed by the system, particularly in sectors such as commercial facilities and critical manufacturing. Users are advised to enhance their security by limiting operator account permissions and considering operational adjustments, such as disabling partitioning if possible.