Executive assessment
Today's brief leads with CC-4839 - ServiceNow Releases Security Advisory for Critical Vulnerabilities in the ServiceNow Now and AI Platforms. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Finding 01 — CC-4839 - ServiceNow Releases Security Advisory for Critical Vulnerabilities in the ServiceNow Now and AI Platforms
What changed: ServiceNow security updates address an 8.7 sandbox escape and three CVSS 10.0 flaws enabling code injection, access-control bypass, or SQL injection across Now and AI platforms. CVE coverage: CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, CVE-2026-74820.
Technical evidence: CVE-2026-18885; CVSS v4.0 10; weakness CWE-94; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst assessment: If patching is not immediately possible, apply generic compensating controls by restricting external access to platform administrative interfaces, API endpoints, and AI integration services via IP allowlists or VPN, enforcing multi-factor authentication, and disabling non-essential public webhooks. In practice, critical weaknesses in an enterprise orchestration and AI platform can permit attackers to bypass access controls, access sensitive business records, or leverage platform automation for lateral movement across connected systems. Watch for unauthorised privilege escalation or new administrator accounts, abnormal REST or Table API traffic, unusual bulk data exports, and unexpected outbound network connections initiated by automated workflows. (Generic reasoning about this weakness class, not vendor-specific guidance; no additional source found.)
Action: Map CVE-2026-18885 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: digital.nhs.uk](<https://digital.nhs.uk/cyber-alerts/2026/cc-4839>)
Finding 02 — WsgiDAV MySQL provider has a blind SQL injection
What changed: WsgiDAV MySQL provider has a blind SQL injection. CVE coverage: CVE-2026-55509.
Technical evidence: CVE-2026-55509; CVSS v4.0 8.8; weakness CWE-89; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-55509 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](<https://github.com/advisories/GHSA-p6gw-4frg-j7jw>)
Finding 03 — USN-8705-1: OpenZFS vulnerability
What changed: USN-8705-1 fixed vulnerabilities in OpenZFS. This update provides the corresponding fix for OpenZFS on Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
Technical evidence: CVE-2026-79619; CVSS v4.0 7.3; weakness CWE-863; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Until patching, restrict /dev/zfs to root or a tightly controlled administrative group, deny the ZFS character device to containers not intentionally delegated ZFS, and do not grant containers CAP_SYS_ADMIN. A public full-disclosure report documents an end-to-end OZ-1-to-OZ-4 exploit chain reaching uid 0 in a research configuration, but states that production-hardened, KASLR-enabled root-shell exploitation was not completed. USN-8705-1 covers Ubuntu 26.04, 24.04 and 22.04 LTS, fixed in zfs-linux package versions 2.4.1-1ubuntu5.1, 2.2.2-0ubuntu9.5 and 2.1.5-1ubuntu6~22.04.7, respectively. ([openwall.com](<https://www.openwall.com/lists/oss-security/2026/08/16/5>), [ubuntu.com](<https://ubuntu.com/security/notices/USN-8705-1>))
Action: Map CVE-2026-79619 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: affected product not structured
[Evidence source: ubuntu.com](<https://ubuntu.com/security/notices/USN-8705-1>)
Finding 04 — Multiple vulnerabilities in TDX
What changed: CVE coverage: CVE-2023-45745, CVE-2024-39283, CVE-2026-20885. The cited advisories disclose: module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access; module software before version TDX_1.5.01.00.592 may allow an authenticated user to potentially enable escalation of privilege via local access; module for some Intel platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege.
Technical evidence: CVE-2023-45745; CVSS v3.1 7.9; weakness CWE-20; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2023-45745 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2023-45745>)
Finding 05 — Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a denial of service.
What changed: Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable remote code execution.
Technical evidence: CVE-2026-20887; CVSS v4.0 8.8; weakness CWE-284; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Intel recommends uninstalling Intel Vision software or discontinuing its use as soon as possible; no patch will be released because the product was discontinued in January 2026. SentinelOne reports no verified public PoC, and CVE-2026-20887 is absent from CISA’s KEV catalogue. All versions are affected, with no fixed version available. ([intel.com](<https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01457.html>), [sentinelone.com](<https://www.sentinelone.com/vulnerability-database/cve-2026-20887/>), [cisa.gov](<https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json>))
Action: Map CVE-2026-20887 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-20887>)
Finding 06 — Improper access control for some Intel: Improper Access Control
What changed: Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege.
Technical evidence: CVE-2026-20716; CVSS v4.0 7.2; weakness CWE-284; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until OEM microcode or firmware can be applied, enforce strict physical access, restrict local interactive logons to trusted administrators, and monitor local authentication and privileged-action logs. SentinelOne reported no public proof of concept or in-the-wild exploitation at publication. Intel lists Xeon 6 P-core server processors, Xeon 6 SoCs and Xeon 6 workstation processors as affected; microcode-20260811 includes INTEL-SA-01435 security updates and lists new revisions 01000434 for GNR-AP/SP, 01000309 for GNR-D and 0a000151 for GNR-SP R1S. ([sentinelone.com](<https://www.sentinelone.com/vulnerability-database/cve-2026-20716/>), [intel.com](<https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html>), [github.com](<https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases>))
Action: Map CVE-2026-20716 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-20716>)
Finding 07 — Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege.
What changed: Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege.
Technical evidence: CVE-2026-20898; CVSS v4.0 8.5; weakness CWE-284; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-20898 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-20898>)
Finding 08 — rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending.
What changed: rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer root. Attackers can exploit multiple variants including implied parent reclassification, synthetic root path construction, legacy protocol behavior below version 30, and non-directory root handling.
Technical evidence: CVE-2026-53789; CVSS v4.0 7.1; weakness CWE-807; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-53789 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-53789>)
Finding 09 — piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
What changed: piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/. CVE coverage: CVE-2026-55485.
Technical evidence: CVE-2026-55485; CVSS v3.1 8.8; weakness CWE-200, CWE-269, CWE-863; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: If patching is not immediately possible, remove the Sessions table from create_admin([...]) or block non-superuser access to GET /api/tables/sessions/. A public proof of concept with complete reproduction steps is available in the maintainer advisory. piccolo-admin versions through 1.13.0 are affected; version 1.14.0 is fixed. ([github.com](<https://github.com/piccolo-orm/piccolo_admin/security/advisories/GHSA-2gh4-jmwq-rr8w>), [github.com](<https://github.com/piccolo-orm/piccolo_admin/releases/tag/1.14.0>))
Action: Map CVE-2026-55485 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](<https://github.com/advisories/GHSA-2gh4-jmwq-rr8w>)
Finding 10 — Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL.
What changed: Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL. CVE coverage: CVE-2026-55245.
Technical evidence: CVE-2026-55245; CVSS v4.0 8.7; weakness CWE-918; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: If patching is delayed, restrict outbound access from the Bifrost gateway to internal/private address ranges and cloud metadata endpoints at the firewall, and disable or closely monitor multimodal image/document URL handling for Bedrock and Vertex. A working public proof of concept is available. Bifrost Core versions before 1.5.17 are affected; version 1.5.17 contains the fix. ([ionix.io](<https://www.ionix.io/threat-center/cve-2026-55245/>), [securelayer7.net](<https://securelayer7.net/lab/cve-2026-55245-bifrost-ispublicip-ssrf-nat64-cgnat-bypass>), [github.com](<https://github.com/advisories/GHSA-w98g-5w9p-p3rc>), [github.com](<https://github.com/maximhq/bifrost/releases/tag/core/v1.5.17>))
Action: Map CVE-2026-55245 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: affected product not structured
[Evidence source: github.com](<https://github.com/advisories/GHSA-w98g-5w9p-p3rc>)
Finding 11 — phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers.
What changed: phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers. CVE coverage: CVE-2026-55584.
Technical evidence: CVE-2026-55584; CVSS v3.1 7.5; weakness CWE-290; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-55584 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](<https://github.com/advisories/GHSA-786w-p5pm-cvgh>)
Finding 12 — GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4.
What changed: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry. CVE coverage: CVE-2026-10053.
Technical evidence: CVE-2026-10053; CVSS v3.1 8.5; weakness CWE-22; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst assessment: Because the advisory specifies no weakness class, apply generic controls for core code-hosting and CI/CD infrastructure: restrict instance ingress to a VPN or trusted IP allowlist, enforce multi-factor authentication, disable public registration, and segment runner networks. In practice, an unclassified application-layer flaw in a DevOps platform exposes source repositories, pipeline credentials, and build environments to potential unauthorised access or tampering. Monitor for anomalous administrative sessions, unexpected personal access token or deploy key generation, atypical repository exports, and unauthorised modifications to CI/CD pipeline configurations. (Generic reasoning about this weakness class, not vendor-specific guidance; no additional source found.)
Action: Map CVE-2026-10053 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-10053>)
Finding 13 — Versa Analytics, the cron jobs: Improper Privilege Management
What changed: In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a potential privilege escalation vulnerability.
Technical evidence: CVE-2018-16497; CVSS v3.1 7.8; weakness CWE-269; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2018-16497 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2018-16497>)
Finding 14 — A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd).
What changed: A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner.
Technical evidence: CVE-2024-6387; CVSS v3.1 8.1; weakness CWE-364; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: If patching is not immediately possible, set LoginGraceTime=0 in sshd_config, restrict SSH using network controls, and monitor for sustained high-volume inbound SSH, anomalous sshd process execution, and pre-authentication 'padding error' or 'message authentication code incorrect' events; disabling the timeout increases denial-of-service exposure. Public proof-of-concept code is available. Portable OpenSSH 8.5p1 through 9.7p1 is affected and fixed in 9.8/9.8p1; versions earlier than 4.4p1 are also vulnerable unless patched for CVE-2006-5051 and CVE-2008-4109. ([openssh.com](<https://www.openssh.com/security.html>), [openssh.org](<https://www.openssh.org/txt/release-9.8>), [offsec.com](<https://www.offsec.com/blog/regresshion-exploit-cve-2024-6387/>), [deepwatch.com](<https://www.deepwatch.com/labs/pocs-released-for-high-severity-vulnerability-cve-2024-6387-in-openssh/>))
Action: Map CVE-2024-6387 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2024-6387>)
Finding 15 — Flowise: Missing Authorization
What changed: Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting the endpoint's inclusion in the global authentication whitelist, which bypasses all session and API key verification. Attackers can supply valid chatflowId, chatId, and fileName identifiers to retrieve files from any chatflow on the instance, including private chatflows belonging to other workspa.
Technical evidence: CVE-2026-71962; CVSS v4.0 8.7; weakness CWE-862; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Block POST requests to /api/v1/openai-assistants-file/download at the reverse proxy and alert on unauthenticated requests or successful 200 responses to that endpoint. A public proof of concept reproduced unauthenticated file retrieval against the official Flowise 3.1.4 release. Versions 2.2.4 through 3.1.4 are affected, and no vendor-supplied fixed version is listed. ([sentinelone.com](<https://www.sentinelone.com/vulnerability-database/cve-2026-71962/>), [gist.github.com](<https://gist.github.com/haidang-infosec/402db84bee7aca2f57bb109b31574649>), [nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-71962>))
Action: Map CVE-2026-71962 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-71962>)