Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: enterprise (4 articles)Clear

Critical SAP kernel flaw lets unauthenticated attackers run commands as admin

SAP patched a critical flaw in its kernel, tracked as CVE-2026-44756 and dubbed OVERPASS with a top score of 10.0, that lets an unauthenticated, remote attacker run commands with administrative privileges and fully compromise a system. The memory-corruption bug is in the Extended Passport processing library and is reachable over several SAP communication protocols, including through the internet-facing Internet Communication Manager, which researchers say exposes more than 10,000 SAP systems online. In the same update SAP fixed a second 10.0 flaw, a missing-authentication issue in the NetWeaver Message Server that lets attackers run code across an entire SAP cluster without credentials. Both need prompt patching.

Check
Apply SAP's September security notes for the kernel and NetWeaver Message Server immediately, and identify any SAP systems whose Internet Communication Manager is reachable from the internet as top priority.
Affected
Organizations running affected SAP systems, especially with an internet-facing Internet Communication Manager (CVE-2026-44756, CVE-2026-58240); unauthenticated remote attackers can execute commands as admin or run code across the whole SAP cluster.
Fix
Patch the SAP kernel and Message Server now, restrict and monitor internet exposure of the Internet Communication Manager and message server ports, and watch for unusual command execution on affected SAP hosts.

Three critical ServiceNow flaws let unauthenticated attackers run code and SQL

ServiceNow patched four flaws in its widely used AI Platform, three of them scored 10.0 and exploitable by an unauthenticated attacker with no user interaction. The first, CVE-2026-18885, is a code injection in the GraphQL Composite Data API that allows arbitrary code execution and access to instance data. The second, CVE-2026-18886, is an access-control flaw in the configuration image-upload processor that lets an attacker create or modify data and escalate privileges. The third, CVE-2026-74820, is a SQL injection allowing arbitrary queries against the instance database. ServiceNow fixed hosted instances itself, but self-managed customers must apply the updates. No exploitation of these three has been reported yet.

Check
Self-hosted ServiceNow customers should apply the platform updates immediately, since ServiceNow only patched its own hosted instances, and confirm production instances are on a fixed version.
Affected
Organizations running the ServiceNow AI Platform, especially self-managed instances (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820); unauthenticated attackers can execute code, manipulate data, escalate privileges, or run arbitrary SQL with no interaction.
Fix
Patch self-hosted instances now, restrict network access to ServiceNow where possible, review logs for suspicious GraphQL requests, unexpected configuration or data changes, and anomalous database queries, and prioritize internet-reachable instances.

Critical Adobe Campaign Classic flaw gives unauthenticated attackers code execution

Adobe patched a critical flaw in Campaign Classic, its enterprise marketing automation platform, that can let an attacker run code without any user interaction. Tracked as CVE-2026-48449 and scored 10.0, it is an incorrect authorization issue leading to arbitrary code execution in the context of the current user. The same update fixes a high-severity SQL injection flaw that allows arbitrary file reads. Affected versions are Campaign Classic v7 build 9397 and earlier on Windows and Linux, mostly on-premises and hybrid deployments, with a fix in build 9398. Adobe says it is not aware of exploitation, and separately patched eight critical flaws in Adobe Bridge.

Check
Identify on-premises or hybrid Adobe Campaign Classic instances, confirm the build number, and update to 7.4.3 build 9398, prioritizing any instance reachable from untrusted networks.
Affected
Organizations running Adobe Campaign Classic v7 build 9397 or earlier (CVE-2026-48449); the incorrect authorization flaw allows code execution with no user interaction, and a companion flaw enables arbitrary file reads.
Fix
Apply Adobe's update to build 9398, restrict access to the Campaign Classic interface, and review the server for unexpected code execution or file access, since the flaw needs no interaction to exploit.

Anthropic launches 'Claude Security' for enterprises - the first major defensive product designed to keep up with AI-powered exploits that compress the time-to-attack to minutes

Anthropic launched Claude Security in public beta yesterday, an enterprise tool that scans code repositories for vulnerabilities, rates each finding's severity and confidence, and generates patch instructions that engineers can apply through Claude Code. The launch is direct response to Mythos and similar AI-driven offensive tools that have been compressing the time between vulnerability disclosure and active exploitation - LiteLLM was exploited 36 hours after disclosure last week, LMDeploy in 13 hours the week before. CrowdStrike, Microsoft Security, Palo Alto Networks, SentinelOne, Trend, and Wiz are integrating Claude Opus 4.7 into their platforms.

Check
If your organization holds a Claude Enterprise subscription, evaluate Claude Security against your existing static analysis tools this week.
Affected
Claude Enterprise customers can access Claude Security in public beta now via claude.ai/security or the Claude.ai sidebar. No API integration required. Team and Max access is coming soon. The deeper relevance is for any security team facing the new exploitation cadence: AI-driven offense has shrunk the patch window for several recent disclosures.
Fix
Pilot Claude Security on a non-critical repository first - point it at a side project before pointing it at production code. Scheduled scans give ongoing coverage rather than one-off audits. Pair the output with Claude Code on the Web to work through patches in a single session. For organizations not on Claude Enterprise: evaluate Aisle, Wiz Code, or GitHub Copilot Autofix on confidence rating and false positive rate.