
ServiceNow CVSS 10 Trio — RCE and SQLi in the Wild
Three CVSS 10.0 ServiceNow AI Platform flaws patched; ZBT routers ship with factory backdoors CVE-2026-74232; PaperCut zero-day exploited in the wild.
Posts tagged: Supply-Chain

Three CVSS 10.0 ServiceNow AI Platform flaws patched; ZBT routers ship with factory backdoors CVE-2026-74232; PaperCut zero-day exploited in the wild.

FBI takes down QTFY Chinese state proxy that breached Federal Reserve and DOJ. CVE-2026-8452 NetScaler exploited in the wild.

CVE-2026-69836 Entra ID max-severity RCE exploited in the wild. AI-generated PLC exploits hit US infrastructure. NetScaler auth bypass patched.

CVE-2026-69836 CVSS 10.0 RCE in Microsoft Entra ID exploited in the wild. Russian APTs abuse OAuth consent flows. Phishing moves inside Slack and Teams.

CVE-2026-65xxx Windows IKE Extension RCE now exploited; Cl0p names 40+ Windchill victims; DOJ charges 17 Iranian Mabna Institute hackers.

CVE-2026-19478 GitLab GraphQL RCE hits CI/CD pipelines. Windows Task Host exploited by ransomware. City Forum scrapes 3.6M Azure records.

White House authorizes private hack-back ops against cybercrime gangs. GeoServer zero-day exploited with no patch. Shell loses 89GB to Clop exfiltration.

NatJack attacks manipulate NAT state to hijack TCP sessions and spoof DNS. Plus Linux SCTP root exploit since 2008 and three Cisco SD-WAN CVSS 9.9 patches.

Cisco patches 24 critical flaws across SD-WAN, IOS XE, and FMC with one public PoC. CVE-2026-63077 TeamCity RCE hits CISA KEV. Oracle DB fileless pivot.

ChainDrop supply chain worm hits 400+ npm packages. CISA KEV adds CVE-2026-9198 Langflow RCE. Iran-linked actors target water systems in 12 US states.