Two individuals sit in front of multiple computer screens, analyzing data and discussing information related to Managed Detection and Response in a dimly lit room with a cityscape visible through the window.

Threat Alerts

Your place for the latest CyberProof cyber threat intelligence alerts and updates

Speak with an Expert
All

ServiceNow AI Platform Authorization and SQLi Flaws

28-Sep-2026
Label: Vulnerability
Threat Level: Medium

Multiple security vulnerabilities were disclosed in the ServiceNow AI Platform that could allow attackers to access, modify, delete, or extract sensitive instance data. The flaws include authorization and access-control weaknesses, as well as a critical SQL injection vulnerability, with several attack paths requiring no authentication.

The vulnerabilities include CVE-2026-86857(CVSS Score 8.4), an authorization bypass allowing authenticated users to access unauthorized AI Platform data; CVE-2026-86858(CVSS Score 8.7), which could allow unauthenticated attackers to create, modify, or delete instance data; and CVE-2026-86859(CVSS Score 8.7), an authorization bypass enabling unauthenticated access to restricted data. The two critical flaws, CVE-2026-13016(CVSS Score 9.3) and CVE-2026-86860(CVSS Score 9.3), could respectively allow unauthenticated attackers to execute arbitrary SQL statements against the underlying database or extract data beyond intended permissions, potentially leading to privilege escalation.

Critical Linux KVM Flaw Enables Guest-to-Host Escape on ARM64 Systems

28-Sep-2026
Label: Vulnerability
Threat Level: Medium

A critical vulnerability in the Linux kernel‘s KVM virtualization layer for ARM64, tracked as CVE-2026-89775 (CVSS 9.8), can expose host kernel memory to guest virtual machines on systems with nested virtualization enabled. The flaw can allow a guest to read and modify host memory, potentially enabling guest-to-host escape and arbitrary code execution on the underlying host.

The vulnerability resides in KVM’s handling of nested virtualization on ARM64. Under specific memory configurations, a size calculation can resolve to zero, causing a required TLB invalidation operation to be skipped. This can leave a freed host memory page mapped and writable from the guest, allowing an attacker to access host memory without triggering a hardware exception. A separate attack path may allow a local unprivileged user to create a virtual machine and exploit the flaw to obtain root-level access, provided nested virtualization is enabled.

Nested virtualization is disabled by default on ARM64 and requires compatible hardware, limiting exposure to systems where the feature has been explicitly enabled. The vulnerability has been fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1, although patch availability varies across Linux distributions. No confirmed active exploitation has been reported, but organizations running ARM64 KVM hosts with nested virtualization enabled should prioritize applying the appropriate kernel updates.

Unauthenticated RCE in SolarWinds Observability

28-Sep-2026
Label: Vulnerability
Threat Level: Medium

Two critical unauthenticated remote code execution flaws were identified in SolarWinds Observability Self-Hosted: CVE-2026-28324 (CVSS Score 9.8) and CVE-2026-28325 (CVSS Score 8.8). Affected instances may allow attackers to execute code remotely without authentication.

CVE-2026-28324 (CVSS Score 9.8) is caused by an insufficient integrity check that can be abused in non-default, non-secure configurations. CVE-2026-28325 (CVSS Score 8.8) involves deserialization of untrusted data when the application runs in a particular communication mode. In both cases crafted, unauthenticated requests to the service can result in remote code execution, potentially compromising monitoring infrastructure and enabling persistence or lateral movement.

A separate high-severity issue, CVE-2026-28326 (CVSS Score 8.8), affecting another module and involving a hardcoded static key was patched recently; all three flaws were flagged as potentially exploitable though no confirmed exploit reports were available.

Critical F5 BIG-IP APM Zero-Day Under Active Exploitation

28-Sep-2026
Label: Vulnerability
Threat Level: Medium

A critical zero-day vulnerability CVE-2026-94127 (CVSS score: 9.8 ) is currently being actively exploited in the wild, targeting F5 BIG-IP Access Policy Manager (APM) systems configured as OAuth authorization servers β€” allowing unauthenticated attackers to execute arbitrary code on affected BIG-IP systems without any credentials. The flaw is a heap-based buffer overflow, Successful exploitation grants full root control of the underlying Linux appliance, enabling attackers to extract private SSL/TLS keys, manipulate internal routing tables, and intercept traffic. Once an edge BIG-IP appliance is compromised, threat actors routinely pivot inward across internal corporate subnets β€” making this not just a perimeter problem, but a potential gateway to full network compromise. Critically, restricting access to the BIG-IP management interface does not protect against this flaw, as the malicious traffic targets the virtual server directly, and BIG-IP systems in Appliance mode are also vulnerable.

Critical GitLab Vulnerabilities Enable Remote Code Execution Through CI/CD Pipelines

28-Sep-2026
Label: Vulnerability
Threat Level: Medium

GitLab released emergency security updates to address two critical vulnerabilities, CVE-2026-89078 and CVE-2026-93577, that could allow authenticated attackers to achieve arbitrary code execution through specially crafted regular expressions embedded in CI/CD configurations.

The first flaw, CVE-2026-89078 (CVSS 9.9), is a double-free vulnerability in GitLab’s regular expression parser. An authenticated attacker can submit a specially crafted regex through a CI/CD configuration, triggering memory corruption that may result in service crashes, manipulation of application execution flow, or arbitrary code execution on the GitLab server.

The second flaw, CVE-2026-93577 (CVSS 9.9), is an integer overflow vulnerability within the regular expression compiler. By supplying a malicious regex pattern during CI/CD processing, an attacker can trigger unsafe memory operations that could ultimately enable arbitrary code execution on affected GitLab instances.

Because GitLab servers commonly store source code, CI/CD secrets, deployment credentials, access tokens, pipeline variables, and build configurations, successful exploitation of either vulnerability could expose sensitive development assets, facilitate credential theft, enable unauthorized modification of build pipelines, and create a substantial software supply chain risk for affected organizations.

Citrix NetScaler Zero Day Exploitation Exposes Enterprise Remote Access Infrastructure

28-Sep-2026
Label: Vulnerability
Threat Level: High

Two critical remote code execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway β€” used across enterprises for VPN, remote access, load balancing, and authentication β€” were confirmed to be actively exploited in the wild, posing a severe risk to organizations before any fix was available. Both flaws were attacked before a public patch existed, making them true zero-days.
The two exploited flaws are CVE-2026-88771 (CVSS Score 9.5), an improper input validation flaw allowing unauthenticated attackers to run arbitrary commands on all deployments regardless of configuration, and CVE-2026-88772 (CVSS Score 9.5), a memory overflow enabling remote code execution or denial-of-service on appliances with DTLS enabled β€” which applies by default to VPN virtual servers unless explicitly disabled. Six additional flaws were disclosed in the same bulletin, though not listed as actively exploited, covering HTTP request smuggling, policy bypass, multiple memory overflows, and a TCP sequence number prediction flaw across various deployment configurations.
Because exploitation preceded the patch release, applying the update alone does not confirm whether an attacker already gained access β€” and prior experience with similar flaws showed that patching does not remove access an attacker may have established beforehand. No workarounds or indicators of compromise were provided alongside the bulletin, leaving organizations in a difficult position when trying to assess whether their environments were targeted before remediation