Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

Three critical ServiceNow flaws let unauthenticated attackers run code and SQL

ServiceNow patched four flaws in its widely used AI Platform, three of them scored 10.0 and exploitable by an unauthenticated attacker with no user interaction. The first, CVE-2026-18885, is a code injection in the GraphQL Composite Data API that allows arbitrary code execution and access to instance data. The second, CVE-2026-18886, is an access-control flaw in the configuration image-upload processor that lets an attacker create or modify data and escalate privileges. The third, CVE-2026-74820, is a SQL injection allowing arbitrary queries against the instance database. ServiceNow fixed hosted instances itself, but self-managed customers must apply the updates. No exploitation of these three has been reported yet.

Check
Self-hosted ServiceNow customers should apply the platform updates immediately, since ServiceNow only patched its own hosted instances, and confirm production instances are on a fixed version.
Affected
Organizations running the ServiceNow AI Platform, especially self-managed instances (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820); unauthenticated attackers can execute code, manipulate data, escalate privileges, or run arbitrary SQL with no interaction.
Fix
Patch self-hosted instances now, restrict network access to ServiceNow where possible, review logs for suspicious GraphQL requests, unexpected configuration or data changes, and anomalous database queries, and prioritize internet-reachable instances.

Attackers exploit PaperCut print server zero-days affecting all NG and MF versions

PaperCut warned that attackers are actively exploiting vulnerabilities in all versions of its widely deployed NG and MF print-management software, and confirmed real customer incidents. Two flaws are involved: CVE-2026-82078, unsafe dynamic class loading in the database connection utilities that lets an attacker run arbitrary Java bytecode, and CVE-2026-81578, an access-control flaw in the web management interface that lets an unauthenticated attacker change system configuration. PaperCut released emergency out-of-cycle patches for its version 25 and 26 branches, with a version 24 build still in progress, and later issued a hardened second release. PaperCut servers have a history of being targeted by ransomware crews.

Check
Install PaperCut's emergency patch, specifically Release 2, on all NG and MF servers now, and if a server is internet-facing, immediately restrict its web interface to trusted IP addresses.
Affected
Organizations running PaperCut NG or MF, especially internet-facing print servers (CVE-2026-82078, CVE-2026-81578); attackers are actively exploiting the flaws to change configuration and execute code, and all versions are affected.
Fix
Apply the emergency Release 2 patch, keep the Application Server off the public internet or limited to trusted IPs, investigate the pc-app process, and treat exposed unpatched servers as compromised.

cPanel flaw lets a low-privilege hosting account seize root on the whole server

A critical flaw in cPanel and WHM, the dominant web hosting control panel, lets a low-privilege but authenticated account take root control of an entire server. Tracked as CVE-2026-65643, the bug lives in the domain-parking feature, which is enabled in virtually every shared and reseller hosting environment. Any account allowed to add parked or addon domains can create arbitrary files anywhere on the underlying server, leading to code execution as root. No advanced skills or chained bugs are needed, only a legitimate low-tier login obtainable through a cheap hosting plan or a compromised account. On shared hosting, one such account can compromise every site, database, and mailbox on the box.

Check
Apply cPanel's patched builds immediately, and while patching, review which accounts can add parked or addon domains and temporarily restrict that permission on unpatched servers.
Affected
Hosting providers and administrators running unpatched cPanel and WHM (CVE-2026-65643); an authenticated account with domain-parking permission can create files as root and take over the whole server, endangering every tenant on it.
Fix
Patch to a fixed cPanel build, confirm automatic updates applied, restrict domain-parking privileges meanwhile, monitor for unexpected files and root processes, and treat any compromised shared server as an incident.

Next.js patches two critical flaws enabling unauthenticated remote code execution

Vercel patched two critical unauthenticated remote code execution flaws in Next.js, the popular React framework that sees tens of millions of downloads a week. One stems from the upstream libheif library used for image processing and triggers when the framework optimizes an attacker-supplied AVIF image; the patched releases disable AVIF optimization until the upstream fix lands. The second, CVE-2026-75604, is a path traversal affecting Next.js servers running on a Windows filesystem in certain router configurations, with no workaround. Fixes are in versions 15.5.24 and 16.3.3, and applications hosted on Vercel are already protected. No exploitation had been reported at disclosure.

Check
Update Next.js to 15.5.24 or 16.3.3, rebuild production containers, and refresh dependency lockfiles, since the AVIF flaw comes through an upstream image library bundled in your build.
Affected
Self-hosted Next.js applications using image optimization or running on Windows filesystems (CVE-2026-75604 and the AVIF flaw); an unauthenticated attacker can achieve remote code execution, though Vercel-hosted apps are already protected.
Fix
Patch and rebuild, disable AVIF optimization until updated, review exposure of the image optimization API and public upload paths, and watch logs for traversal patterns and unusual AVIF processing on Windows-hosted instances.

China-made ZBT routers ship with factory backdoors granting unauthenticated root

Researchers at VulnCheck found two undocumented factory implants in the firmware of routers made by the Chinese manufacturer ZBT, each giving a remote, unauthenticated attacker the ability to run commands as root. Named SPEAKINGSTONE and DARKLANTERN and tracked as CVE-2026-74232 and CVE-2026-74233, both scored around 9.3, require no privileges or interaction. SPEAKINGSTONE runs as a hidden service and beacons out over a fixed UDP port to a hardcoded command-and-control server; because it dials outward, it works from behind network address translation and normal egress filtering. The findings underscore the supply-chain risk of low-cost networking hardware with opaque firmware.

Check
Identify any ZBT or Zbtlink routers in your environment, isolate or replace affected models, and block outbound traffic to the implant's command-and-control server and its fixed UDP port.
Affected
Anyone operating affected ZBT-manufactured routers, including rebranded models; the built-in implants let a remote unauthenticated attacker gain root, and one beacons out to a hardcoded server, working even from behind NAT.
Fix
Replace untrustworthy OEM networking gear, segment and monitor such devices, block known implant command-and-control destinations, inspect egress for beaconing on the implicated port, and prefer vendors with transparent, verifiable firmware.

Malicious repository content can make Amazon's Kiro AI IDE leak local data

Researchers showed that Amazon Kiro, an AI-powered agentic development environment, can be turned against its user through prompt injection. Attacker-controlled content in a repository the developer opens can steer the Kiro agent into transmitting sensitive local information to an external server, abusing a feature called Kiro Powers that bundles model context protocol server configurations, steering files, and hooks. The developer only has to open the workspace and interact with the agent. It is part of a wider run of similar flaws in AI coding tools, where untrusted content or links quietly redirect an agent into exfiltrating data or executing code without any approval prompt. Updating the tool addresses the reported issue.

Check
Update Kiro to the latest version, and treat opening untrusted repositories in any agentic AI development environment as risky, since hidden instructions can drive the agent without an approval prompt.
Affected
Developers using Amazon Kiro or similar agentic AI IDEs who open untrusted repositories; malicious content can prompt-inject the agent to exfiltrate local data or alter its own tool and context configuration files.
Fix
Keep agentic IDEs updated, review model context protocol configs and steering files for tampering, limit what secrets and paths the agent can reach, and avoid opening untrusted projects in autonomous tools.

GPUThor Rowhammer defeats ECC on NVIDIA GPUs to reach host root

Academic researchers disclosed GPUThor, a Rowhammer attack that defeats the error-correcting memory that NVIDIA recommends as the defense against GPU Rowhammer. Demonstrated on Ampere-class workstation GPUs with GDDR6 memory, including the RTX A4000 through A6000 models common in AI and cloud infrastructure, it lets unprivileged code running on the GPU flip memory bits far more reliably than earlier attacks, finding an exploitable flip in about a minute. That enables denial of service, silent data corruption, and escalation to a root shell on the host. The researchers note error correction is not sufficient protection, which matters most where untrusted workloads share GPUs, as in multi-tenant cloud and AI platforms.

Check
Where GPUs run untrusted or multi-tenant workloads, avoid sharing a physical GPU across tenants, limit who can run arbitrary GPU code, and monitor for unusual error-correction events on affected NVIDIA cards.
Affected
Systems running untrusted GPU workloads on affected NVIDIA Ampere workstation cards with GDDR6 memory; unprivileged GPU code can flip memory bits despite error correction, causing denial of service or host root access.
Fix
Isolate GPU workloads and avoid cross-tenant sharing of physical GPUs, restrict arbitrary code execution on shared GPUs, monitor error-correction telemetry for hammering, and follow vendor guidance as hardware-level mitigations develop.

Attackers exploit a critical Gitea flaw to run code on self-hosted Git servers

CISA warned that attackers are exploiting a critical flaw in Gitea, the popular self-hosted Git service, and added it to its exploited-vulnerabilities catalog. Tracked as CVE-2026-60004 and scored 9.8, the code-injection bug lets a user with repository write access send a malicious patch to the diffpatch API endpoint, planting an executable Git hook that runs shell commands as the Gitea service account. Crucially, default installations have open self-registration, so an unauthenticated attacker can simply register, create a repository, and gain code execution. It affects versions 1.17 through 1.27.0 and was fixed in July, and reports describe attackers dropping cryptocurrency miners, with one intrusion taking about eleven seconds.

Check
Upgrade Gitea to 1.27.1 or later immediately, disable open self-registration on internet-facing instances, and treat any exposed, registration-enabled server as an incident-response case rather than just a patch.
Affected
Organizations running self-hosted Gitea 1.17 through 1.27.0 (CVE-2026-60004); an attacker with repository write access, obtainable through default open registration, can execute shell commands as the Gitea service account.
Fix
Patch to a fixed release, turn off self-registration where not needed, restrict internet exposure of Gitea, and hunt patched servers for rogue Git hooks, miner processes, and other signs of compromise.

Malicious webpage can hijack a local AI agent via NVIDIA NemoClaw and Ollama

Researchers disclosed a flaw in NVIDIA NemoClaw, a stack for running AI agents like OpenClaw with local inference through Ollama, that lets a single malicious webpage hijack the agent. Tracked as CVE-2026-65105, the issue is that NemoClaw starts Ollama bound to all network interfaces, so a DNS-rebinding attack from a page the user simply visits reaches the local model server and takes unauthenticated control. The attacker can then rewrite the model's chat template to plant hidden instructions that run on every later inference, beneath the agent's own guardrails and persisting across conversations. A fix landed in version 0.0.35 for macOS and Linux, but the Windows path remains exposed.

Check
Update NemoClaw to 0.0.35 on macOS and Linux, bind Ollama to the loopback address instead of all interfaces, and firewall port 11434, treating the local model server as a critical service.
Affected
Developers running NemoClaw with a local Ollama backend (CVE-2026-65105); a visited malicious page can hijack the model server via DNS rebinding and persistently poison the model, with the Windows path still unfixed.
Fix
Patch where a fix exists, restrict Ollama to loopback and firewall its port, monitor for chat-template changes, and limit the tools, source control, and cloud access the agent holds to reduce impact.

Unpatched Kaltura video player flaws allow unauthenticated file read and code execution

CERT/CC disclosed two unpatched flaws in Kaltura's HTML5 video player library that let a remote, unauthenticated attacker read files from a server and run code, with only network access to the endpoint required. Both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint, which takes a user-controlled ServiceUrl parameter and passes fetched data to PHP's unserialize without validating it. Supplying a file path lets an attacker read any file the web server can access, including credentials and API keys, while the deserialization also enables code execution. CERT/CC could not reach the vendor, and because the endpoint is exposed on Kaltura's shared multi-tenant infrastructure, the flaws can affect many tenants at once.

Check
Since there is no vendor patch, restrict or disable external access to the mwEmbedLoader.php endpoint and enforce a strict allow-list for the ServiceUrl parameter permitting only known backend API URLs.
Affected
Organizations running the Kaltura HTML5 player library exposing mwEmbedLoader.php (CVE-2026-19913, CVE-2026-19912); an unauthenticated attacker can read sensitive files and execute code, with shared-CDN exposure widening the impact.
Fix
Block or lock down the vulnerable endpoint, allow-list ServiceUrl values, monitor for suspicious file-read attempts, rotate any secrets that may have been exposed, and watch for a vendor fix.