- Sandbox escape in the Now Platform
- SQL injection vulnerability in dynamic schema ORDER BY clause
- Improper access control vulnerability in system configuration image upload processor
- Pre-authentication sandbox escape previously disclosed and observed in the wild
- Code injection vulnerability in GraphQL Composite Data API
ThreatNoir Afternoon Brief — August 28
Afternoon Review in IT Security — August 28, 2026
The technology sector faces mounting pressure as critical vulnerabilities continue to emerge across widely deployed infrastructure platforms. Today's security landscape reveals systemic weaknesses in cloud services, networking equipment, and hosting management systems that demand immediate attention from organizations worldwide.
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow has released patches addressing four security flaws impacting the ServiceNow AI Platform, with three vulnerabilities receiving the maximum CVSS 10.0 rating. These critical issues can be exploited in certain circumstances by unauthenticated attackers to execute arbitrary code and conduct SQL injection attacks. The company deployed security updates to its hosted instances and provided patches to partners and self-hosted customers, though organizations managing their own infrastructure must take independent action to remediate the risks. The affected CVE identifiers include CVE-2026-18885, CVE-2026-18886, CVE-2026-6875, CVE-2026-6876, and CVE-2026-74820. Source: Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
VulnCheck has disclosed two previously undocumented factory implants embedded in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT). The implants, designated SPEAKINGSTONE and DARKLANTERN by the zero-day research team, enable unauthenticated remote attackers to execute commands with root privileges on affected devices. These factory-installed backdoors represent a significant supply chain compromise, as they are tracked under CVE-2026-74232 and CVE-2026-74233. Organizations deploying ZBT networking equipment face immediate risk from these pre-installed vulnerabilities that bypass standard authentication mechanisms. Source: China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
ServiceNow Warns of Three Max Severity Security Vulnerabilities
ServiceNow has issued warnings regarding three maximum-severity vulnerabilities in its AI Platform that facilitate code injection, SQL injection, and privilege escalation attacks. The company released security patches addressing these critical flaws to mitigate exploitation risks across its customer base. The vulnerabilities are tracked under multiple CVE identifiers including CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217, alongside the previously mentioned 2026-era CVEs. Organizations running ServiceNow infrastructure must prioritize patching these maximum-severity issues to prevent unauthorized access and data compromise. Source: ServiceNow warns of three max severity security vulnerabilities
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
cPanel has released patches for a critical security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM). The vulnerability, identified as CVE-2026-65643, impacts all supported versions of cPanel & WHM and could allow code execution with root user privileges. This flaw presents a severe risk in shared hosting environments where a compromised customer account could potentially grant attackers complete control over the entire server infrastructure. Additional related CVE identifiers include CVE-2026-41940, CVE-2026-48172, and CVE-2026-54420. Source: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
The convergence of critical vulnerabilities across ServiceNow, ZBT routers, and cPanel infrastructure underscores the urgent need for comprehensive patching strategies and supply chain security reviews. Organizations should prioritize immediate remediation efforts while reassessing their vendor security practices to prevent future compromise.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- DARKLANTERN implant vulnerability
- SPEAKINGSTONE implant vulnerability
- Previously exploited ServiceNow vulnerability.
- Maximum severity AI Platform vulnerability allowing privilege escalation.
- Previously exploited ServiceNow vulnerability.
- Maximum severity AI Platform vulnerability allowing code injection.
- Previously exploited ServiceNow vulnerability.
- High-severity sandbox escape vulnerability in AI Platform.
- Maximum severity AI Platform vulnerability allowing SQL injection.
- Previously exploited pre-auth sandbox escape vulnerability in AI Platform.
- Symlink-following flaw in LiteSpeed cPanel plugin.
- Critical cPanel vulnerability allowing root code execution.
- Privilege escalation in LiteSpeed cPanel plugin.
- Authentication bypass patched in April, used in ransomware.