Overview
- ServiceNow
- ServiceNow AI Platform
27 Aug 2026
Published
28 Aug 2026
Updated
CVSS v4.0
CRITICAL (10.0)
EPSS
0.26%
KEV
Description
ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation.
ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of exploitation against ServiceNow instances.
We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Statistics
- 2 Posts
- 1 Interaction
Last activity: 10 hours ago
Fediverse
ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.
Overview
- PaperCut
- PaperCut MF/NG
28 Aug 2026
Published
28 Aug 2026
Updated
CVSS v4.0
CRITICAL (9.4)
EPSS
Pending
KEV
Description
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- PaperCut
- PaperCut MF/NG
28 Aug 2026
Published
28 Aug 2026
Updated
CVSS v4.0
HIGH (8.8)
EPSS
Pending
KEV
Description
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Unitree Robotics
- G1 EDU
27 Aug 2026
Published
28 Aug 2026
Updated
CVSS v4.0
HIGH (7.7)
EPSS
0.35%
KEV
Description
Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentials by exploiting an unquoted heredoc variable in the WiFi provisioning script and a buffer overflow in the SSID chunk accumulator. Attackers can send crafted BLE writes to overflow a fixed BSS buffer across BLE connections, corrupting an adjacent mainloop function pointer dispatch entry that is subsequently invoked by the cleanup path passing attacker-controlled data to system() as uid 0.
Statistics
- 1 Post
Last activity: 10 hours ago
Overview
- ServiceNow
- ServiceNow AI Platform
27 Aug 2026
Published
28 Aug 2026
Updated
CVSS v4.0
CRITICAL (10.0)
EPSS
0.24%
KEV
Description
ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended.
ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances.
We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Statistics
- 1 Post
- 1 Interaction
Last activity: 20 hours ago
Fediverse
ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.