[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqCMtbKJiNI2JYn-MfsZJBeZUzA5fLzq4sVvCl-CY6ps":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"46f49629-8d28-4e5b-9aff-2da5c8821ee6","critical-patches-released-by-fortinet-ivanti-and-servicenow-act-before-exploitation-begins","9ac0973a-219f-412f-9227-cebe798612f8","Critical Patches Released by Fortinet, Ivanti, and ServiceNow — Act Before Exploitation Begins","Three major enterprise software vendors simultaneously released patches covering 15 vulnerabilities, including a critical unauthenticated remote code execution flaw in ServiceNow's AI platform scoring 9.5 on the CVSS scale. The window between patch release and active exploitation by threat actors is shrinking — historically, critical vulnerabilities in widely-used platforms like these are weaponized within days. Organizations running ServiceNow, Ivanti Xtraction, FortiOS, FortiAuthenticator, or FortiSandbox are at elevated risk until patches are applied. Unauthenticated RCE flaws are especially dangerous because they require no credentials, meaning any internet-exposed instance is a potential entry point for full system compromise.","**Immediate actions:**\n- Apply all vendor-released patches immediately, prioritizing the ServiceNow CVE-2026-6875 (CVSS 9.5) unauthenticated RCE vulnerability above all others.\n- Perform an emergency audit of internet-facing instances of ServiceNow, Ivanti Xtraction, FortiOS, FortiAuthenticator, and FortiSandbox to identify unpatched systems.\n- Temporarily restrict public-facing access or apply vendor-recommended mitigations for any system that cannot be patched immediately.\n\n**Long-term improvements:**\n- Maintain a continuously updated asset inventory that maps every software version and patch status across your environment.\n- Implement a formal vulnerability management lifecycle with defined SLAs — e.g., critical (CVSS 9.0+) patches applied within 24–72 hours.\n- Subscribe to vendor security advisories and threat intelligence feeds to receive real-time patch notifications.\n\n**Detection measures:**\n- Deploy automated vulnerability scanning tools (e.g., Tenable, Qualys) to continuously assess patch compliance across all enterprise assets.\n- Monitor logs and SIEM alerts for anomalous activity targeting affected systems, even if no exploitation has been publicly reported yet.\n- Establish a baseline of normal behavior on critical platforms so that exploitation attempts can be detected rapidly.",[12,13,14,15,16,17,18,19,20],"CIS Control 7: Continuous Vulnerability Management","CIS Control 2: Inventory and Control of Software Assets","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning","NIST SI-2: Flaw Remediation","NIST RA-5: Vulnerability Monitoring and Scanning","NIST CM-8: System Component Inventory","ITIL Change Management: Emergency Change Procedures","ISO\u002FIEC 27001 A.12.6.1: Management of Technical Vulnerabilities","GDPR Article 32: Security of Processing (patch management as a technical safeguard)","published","2026-07-15T12:20:55.42049+00:00","2026-07-15T12:20:55.157+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.securityweek.com\u002Fvulnerabilities-patched-by-fortinet-ivanti-servicenow\u002F","vulnerabilities-patched-by-fortinet-ivanti-servicenow-912788","Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]