
ServiceNow CVSS 10 Trio — RCE and SQLi in the Wild
Three CVSS 10.0 ServiceNow AI Platform flaws patched; ZBT routers ship with factory backdoors CVE-2026-74232; PaperCut zero-day exploited in the wild.
Posts tagged: Cisa-Kev

Three CVSS 10.0 ServiceNow AI Platform flaws patched; ZBT routers ship with factory backdoors CVE-2026-74232; PaperCut zero-day exploited in the wild.

CVE-2026-73570 compromises 270+ Zimbra servers with CISA 72-hour deadline. Plus CVE-2026-21962 Oracle WebLogic CVSS 10.0 and Iranian OT attacks.

Talos exposes AI-generated Linux rootkit in SPECTRE campaign. NSA confirms AI in OT attacks. Critical Cisco Crosswork and Citrix NetScaler auth bypasses.

81M password-spray attempts exploit legacy auth protocols that bypass MFA. Plus CVE-2026-65400 macOS auth bypass on CISA KEV and TWINLOOT C2 inside M365.

CVE-2026-65xxx Windows IKE Extension RCE now exploited; Cl0p names 40+ Windchill victims; DOJ charges 17 Iranian Mabna Institute hackers.

CVE-2026-19478 GitLab GraphQL RCE hits CI/CD pipelines. Windows Task Host exploited by ransomware. City Forum scrapes 3.6M Azure records.

CISA adds Progress LoadMaster and SonicWall SMA1000 CVSS 10 to KEV; FBI warns of Gunra ransomware hitting FortiOS and Schneider Electric flaws.

Progress LoadMaster CVSS 10 RCE added to CISA KEV with active exploitation. Iranian actors pivot through private APN to hit Polish energy.

Cisco patches 24 critical flaws across SD-WAN, IOS XE, and FMC with one public PoC. CVE-2026-63077 TeamCity RCE hits CISA KEV. Oracle DB fileless pivot.

ChainDrop supply chain worm hits 400+ npm packages. CISA KEV adds CVE-2026-9198 Langflow RCE. Iran-linked actors target water systems in 12 US states.