The vulnerability stems from flaws in the plugin's handling of "direct request" mode, where it accepted requests without proper cryptographic verification.
ServiceNow has addressed a critical vulnerability within its AI Platform that could have allowed threat actors to impersonate users and execute arbitrary actions.
The vulnerability, identified as CVE-2026-20805, affects the Windows Desktop Window Manager and allows attackers to leak small pieces of memory information.
Multiple iterations of the Apache Struts 2 open-source web application framework have been impacted by the high-severity XML external entity injection vulnerability, tracked as CVE-2025-68493, which could be exploited to facilitate data exposure, as well as denial-of-service and server-side request forgery intrusions, GBHackers News reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.