
ServiceNow CVSS 10 Trio — RCE and SQLi in the Wild
Three CVSS 10.0 ServiceNow AI Platform flaws patched; ZBT routers ship with factory backdoors CVE-2026-74232; PaperCut zero-day exploited in the wild.
Posts tagged: Daily-Brief

Three CVSS 10.0 ServiceNow AI Platform flaws patched; ZBT routers ship with factory backdoors CVE-2026-74232; PaperCut zero-day exploited in the wild.

FBI takes down QTFY Chinese state proxy that breached Federal Reserve and DOJ. CVE-2026-8452 NetScaler exploited in the wild.

CVE-2026-73570 breaches 270+ Zimbra servers; CISA flags 100+ water systems targeted via exposed OT; Gitea RCE CVE-2026-60004 hits KEV.

CVE-2026-73570 compromises 270+ Zimbra servers with CISA 72-hour deadline. Plus CVE-2026-21962 Oracle WebLogic CVSS 10.0 and Iranian OT attacks.

CVE-2026-18963 allows unauthenticated Keycloak password resets. Plus Iran-linked OT attack shuts UK power plant and Spring ships 91 CVE patches.

CVE-2026-69836 Entra ID max-severity RCE exploited in the wild. AI-generated PLC exploits hit US infrastructure. NetScaler auth bypass patched.

Talos exposes AI-generated Linux rootkit in SPECTRE campaign. NSA confirms AI in OT attacks. Critical Cisco Crosswork and Citrix NetScaler auth bypasses.

CVE-2026-65xxx Windows IKE Extension RCE now exploited; Cl0p names 40+ Windchill victims; DOJ charges 17 Iranian Mabna Institute hackers.

CVE-2026-19478 GitLab GraphQL RCE hits CI/CD pipelines. Windows Task Host exploited by ransomware. City Forum scrapes 3.6M Azure records.

CVE-2026-59310 vCenter RCE exploited by China-nexus APT for Babuk ransomware. Plus Clop claims GE and Philips, SAP Commerce Cloud hit in 3 days.