
ServiceNow CVSS 10 Trio — RCE and SQLi in the Wild
Three CVSS 10.0 ServiceNow AI Platform flaws patched; ZBT routers ship with factory backdoors CVE-2026-74232; PaperCut zero-day exploited in the wild.
Posts tagged: Zero-Day

Three CVSS 10.0 ServiceNow AI Platform flaws patched; ZBT routers ship with factory backdoors CVE-2026-74232; PaperCut zero-day exploited in the wild.

CVE-2026-73570 breaches 270+ Zimbra servers; CISA flags 100+ water systems targeted via exposed OT; Gitea RCE CVE-2026-60004 hits KEV.

CVE-2026-73570 compromises 270+ Zimbra servers with CISA 72-hour deadline. Plus CVE-2026-21962 Oracle WebLogic CVSS 10.0 and Iranian OT attacks.

CVE-2026-18963 lets unauthenticated attackers reset any Keycloak account. Plus SynkLoader steals creds via fake lock screens and Teams blocks bots.

CVE-2026-69836 Entra ID max-severity RCE exploited in the wild. AI-generated PLC exploits hit US infrastructure. NetScaler auth bypass patched.

Talos exposes AI-generated Linux rootkit in SPECTRE campaign. NSA confirms AI in OT attacks. Critical Cisco Crosswork and Citrix NetScaler auth bypasses.

CVE-2026-19478 GitLab GraphQL RCE hits CI/CD pipelines. Windows Task Host exploited by ransomware. City Forum scrapes 3.6M Azure records.

CVE-2026-59310 vCenter RCE exploited by China-nexus APT for Babuk ransomware. Plus Clop claims GE and Philips, SAP Commerce Cloud hit in 3 days.

White House authorizes private hack-back ops against cybercrime gangs. GeoServer zero-day exploited with no patch. Shell loses 89GB to Clop exfiltration.

CVE-2026-20349 crashes Cisco firewalls remotely. Microsoft patches 398 flaws with one exploited zero-day. VMware vCenter CVSS 9.8 RCE now in the wild.