← nejvýznamnější zprávy · všechny zprávy

SPOJENO AI EPSS 0.00 (nejvyšší)

ServiceNow warns of three max severity security vulnerabilities

ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. [...]

Číst originál na BleepingComputer →

4 zprávy z 4 zdrojů · první 28. 8. 04:00 · poslední 28. 8. 15:43 CZ · EN/orig

ServiceNow CA US IT FI

tg: zneužíváno tg: zranitelnost

CVE v události 4

CVEhodnoceníKEVEPSS
CVE-2026-18885 10.0 4.0 · SN 0.00
CVE-2026-18886 10.0 4.0 · SN 0.00
CVE-2026-6876 10.0 4.0 · SN 0.00
CVE-2026-74820 10.0 4.0 · SN 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 10.0.

Text zpravodajského článku zmiňuje ještě chyby CVE-2024-4879, CVE-2024-5178, CVE-2024-5217, CVE-2026-6875. Tahle čísla radar vytáhl z textu článku, ne ze seznamu chyb, který zpráva uvádí, takže u nich neukazuje fakta z katalogů ani v tabulce výš; najdete je na stránkách těch CVE.

Jak se o tom psalo 4

  1. · Cyber Centre Kanada CA

    ServiceNow security advisory (AV26-857)

    Serial number: AV26-857Date: August 28, 2026 As of August 27, 2026, ServiceNow is affected by vulnerabilities in the following products: Xanadu Versions prior to Patch 11 Hot Fix 7a Yokohama Versions prior to Yokohama Patch 12 Hot Fix 3b Versions prior to Yokohama Patch 13 Hot Fix 4 Zurich Multiple versions Australia Multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. August 2026 CVE…

  2. · BleepingComputer US nadpis události

    ServiceNow warns of three max severity security vulnerabilities

    ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. [...]

  3. · CSIRT Itálie (ACN) IT

    Aggiornamenti di sicurezza sanano molteplici vulnerabilità in ServiceNow

    Rilasciati aggiornamenti di sicurezza che sanano 4 vulnerabilità ,di cui una con gravità "alta" e 3 con gravità "critica", presenti nella piattaforma ServiceNow. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un attaccante non autenticato di eseguire codice arbitrario, manipolare dati delle istanze e ottenere privilegi elevati sui sistemi interessati.

  4. · NCSC-FI FI

    ServiceNow - ServiceNow AI platform vulnerabilities

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, Summary: On August 27, 2026, ServiceNow issued CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820 regarding the underlying logic that allowed for the reported security issues. Each of these security issues was identified through ServiceNow's security research and responsible disclosure programs and remediated…