ServiceNow Rushes Fixes for Five AI Platform Bugs After Two Are Rated Critical
ServiceNow has patched five vulnerabilities in its AI Platform, including a SQL injection flaw and a missing-authorization bug that together could let an unauthenticated attacker read, alter, or...
Actively Exploited Roundcube Flaw Lets Attackers Slip Past the Login Screen Entirely
Canadian cybersecurity officials have confirmed active, in-the-wild exploitation of a pre-authentication SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842. The flaw requires no valid credentials to exploit,...
Attackers Are Already Probing a Critical Flaw in Sangoma’s Switchvox VoIP Platform
A critical, unauthenticated SQL injection flaw in Sangoma Switchvox is being actively probed in the wild just weeks after a patch became available. With thousands of phone systems...
A Popular WordPress Backup Plugin’s Flaw Puts 5 Million Sites One Restore Away From Takeover
A high-severity SQL injection flaw in the All-in-One WP Migration and Backup plugin, installed on more than five million WordPress sites, can be triggered through the platform's own...
Critical ServiceNow AI Flaws Expose Enterprise Data and Code Execution Paths
ServiceNow has patched three critical AI-platform vulnerabilities and a high-severity Now Platform sandbox escape. Self-hosted customers should urgently verify fixed releases and investigate signs of unauthorized code execution...
Unpatched GeoServer Zero-Day Under Active Attack as Researchers Warn of RCE Risk
A newly disclosed, unpatched SQL injection flaw in the open-source mapping platform GeoServer is already being probed by attackers just hours after it went public. Under certain database...
Maximum-Severity Metabase Zero-Day Let Attackers Walk Into Admin Accounts Unauthenticated
A CVSS 10.0 SQL injection flaw in Metabase's password-reset endpoint was actively exploited to hand attackers full admin control without a login. Metabase Cloud was breached before a...
APT Campaign Exploits cPanel CVE-2026-41940 to Breach Government and Military Servers Across South-East Asia
A sophisticated threat actor has exploited the critical cPanel authentication bypass CVE-2026-41940 to compromise government and military servers across South-East Asia, while also deploying a custom zero-day SQL-to-OS...