OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek.
CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, including a critical authentication flaw in ownCloud Server's WebDAV functionality with a CVSS score of 9.8, alongside flaws in the Linux Kernel and JFrog Artifactory. These additions to the KEV catalog indicate that threat actors are actively exploiting these vulnerabilities in the wild, making them priority targets for patching across affected organizations.
Security researcher Olivier Laflamme discovered two independent root RCE vulnerabilities in the Unitree G1 EDU humanoid robot, tracked as CVE-2026-76639 and CVE-2026-76640. One attack path exploits chat_go and bashrunner over the network, while the other leverages Bluetooth Low Energy to achieve root access on the robot's Locomotion PC.
CISA has highlighted that the majority of actively exploited vulnerabilities represent security flaws that should have been eliminated years ago, pointing to persistent organizational culture issues and incomplete adoption of Secure by Design principles as root causes. The agency's assessment suggests that systemic gaps in security practices continue to leave organizations vulnerable to preventable attacks rather than zero-day exploits.
ServiceNow addressed four security vulnerabilities affecting its AI Platform, with three receiving a critical CVSS 10.0 rating that could allow unauthenticated attackers to execute code and SQL queries under certain conditions. The vendor deployed patches to its hosted instances and made updates available to partners and self-hosted customers, though organizations running self-hosted deployments will need to apply fixes independently. The disclosure underscores the importance of promptly patching critical flaws in widely-deployed enterprise platforms.