Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow addressed four security vulnerabilities affecting its AI Platform, with three receiving a critical CVSS 10.0 rating that could allow unauthenticated attackers to execute code and SQL queries under certain conditions. The vendor deployed patches to its hosted instances and made updates available to partners and self-hosted customers, though organizations running self-hosted deployments will need to apply fixes independently. The disclosure underscores the importance of promptly patching critical flaws in widely-deployed enterprise platforms.
CISA has highlighted that the majority of actively exploited vulnerabilities represent security flaws that should have been eliminated years ago, pointing to persistent organizational culture issues and incomplete adoption of Secure by Design principles as root causes. The agency's assessment suggests that systemic gaps in security practices continue to leave organizations vulnerable to preventable attacks rather than zero-day exploits.
A critical vulnerability in cPanel and WebHost Manager (WHM) affecting domain parking and addon domain functionality could allow a hosting customer to execute code with root privileges on a shared server. The flaw, tracked as CVE-2026-65643, impacts all supported versions of the platform and has prompted cPanel to release patches. This represents a significant privilege escalation risk in multi-tenant hosting environments where multiple customers share the same server infrastructure.
PaperCut Software is warning of active exploitation of a zero-day vulnerability affecting its NG and MF print management products, with attackers currently leveraging the flaw in the wild. The company has released emergency patches to address the issue, though technical details and CVE assignment have not yet been disclosed. Organizations using PaperCut's affected products should prioritize applying the available patches to mitigate immediate risk.
CISA has added multiple vulnerabilities affecting Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler to its Known Exploited Vulnerabilities catalog, indicating these flaws are actively being exploited in the wild. The additions include CVE-2015-3246, a race condition in Red Hat libuser, among other critical issues across diverse platforms and components. Organizations running these affected products should prioritize patching to mitigate active exploitation risks.