24h | 7d | 30d

Overview

  • ServiceNow
  • ServiceNow AI Platform

27 Aug 2026
Published
28 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.26%

KEV

Description

ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of exploitation against ServiceNow instances.  We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 10 hours ago

Fediverse

Profile picture fallback

ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.

securityonline.info/servicenow

  • 1
  • 0
  • 0
  • 20h ago

Bluesky

Profile picture fallback
ServiceNow patched three max-severity AI Platform flaws enabling code injection, SQL injection, and privilege escalation, plus a high-severity sandbox escape bug. #ServiceNow #CVE202618885 #CVE202618886
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • PaperCut
  • PaperCut MF/NG

28 Aug 2026
Published
28 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
Pending

KEV

Description

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
PaperCut issued Emergency Patch Release 2 for NG and MF after researchers bypassed the original fix for two actively exploited flaws that can enable auth bypass and remote code execution. #PaperCut #CVE202681578 #CVE202682078
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • PaperCut
  • PaperCut MF/NG

28 Aug 2026
Published
28 Aug 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
Pending

KEV

Description

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
PaperCut issued Emergency Patch Release 2 for NG and MF after researchers bypassed the original fix for two actively exploited flaws that can enable auth bypass and remote code execution. #PaperCut #CVE202681578 #CVE202682078
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Unitree Robotics
  • G1 EDU

27 Aug 2026
Published
28 Aug 2026
Updated

CVSS v4.0
HIGH (7.7)
EPSS
0.35%

KEV

Description

Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentials by exploiting an unquoted heredoc variable in the WiFi provisioning script and a buffer overflow in the SSID chunk accumulator. Attackers can send crafted BLE writes to overflow a fixed BSS buffer across BLE connections, corrupting an adjacent mainloop function pointer dispatch entry that is subsequently invoked by the cleanup path passing attacker-controlled data to system() as uid 0.

Statistics

  • 1 Post

Last activity: 10 hours ago

Bluesky

Profile picture fallback
Two independent root RCE chains affect the Unitree G1 EDU, including a BLE path to root on the Locomotion PC, tracked as CVE-2026-76639 and CVE-2026-76640.
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • ServiceNow
  • ServiceNow AI Platform

27 Aug 2026
Published
28 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.24%

KEV

Description

ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances.  We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 20 hours ago

Fediverse

Profile picture fallback

ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.

securityonline.info/servicenow

  • 1
  • 0
  • 0
  • 20h ago
Showing 41 to 45 of 45 CVEs