VulncastBriefing archive

Daily Brief - 2026-09-25

· 5 vulnerabilities · 7 min listen

▶ Listen to this briefing

CVE-2026-13016

ServiceNow AI Platform

ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

  • SQL Injection
  • web application
  • database

CVE-2026-82093

high · CVSS 8.8 · IBM DataStage

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.

  • Insecure Deserialization
  • Remote Code Execution
  • data integration
  • cloud platform

CVE-2026-82157

high · CVSS 8.3 · Dell ThinOS

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Protection mechanism bypass and Unauthorized access.

  • Security Bypass
  • Unauthorized Access
  • thin client
  • operating system

CVE-2026-87739

PaperCut MF/NG

An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information.

  • Improper Authentication
  • print management server

CVE-2026-93577

critical · CVSS 9.9 · GitLab CE/EE

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.

  • Remote Code Execution
  • Integer Overflow
  • web application