Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution.
The vulnerability, a severe SQL injection flaw with a CVSS score of 9.3, affects Sangoma Switchvox SMB Edition 8.3 (104997).
A threat actor is targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586).
ServiceNow has patched three maximum-severity vulnerabilities, including two leading to remote code execution.
ServiceNow patched three CVSS 10.0 flaws letting unauthenticated attackers run code and SQL inside its AI Platform, the base ...
The second critical advisory in five weeks exposes how AI agent workflows amplify the blast radius of infrastructure flaws in enterprise environments.
ServiceNow patched four flaws, including three critical bugs enabling code execution, data theft, and privilege escalation.
The vulnerabilities can be exploited remotely without user interaction; security teams should also look beyond ServiceNow to ...
The agency examined soft spots across 2024 and 2025, finding that the majority of those that receive CVEs and make it to the ...
ServiceNow patched four AI Platform flaws, including three CVSS 10.0 bugs that can enable unauthenticated code execution or ...
ServiceNow has released security updates for four vulnerabilities, including three rated critical, that could allow ...
ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code ...