Vulnerability Alert7 August 2026
ServiceNow AI Platform Flaw (CVE-2026-6875) Now Under Active Exploitation
A pre-authentication sandbox-escape bug in ServiceNow's AI Platform is being exploited in the wild via a second gadget chain, weeks after a patch and public disclosure.
servicenowcve-2026-6875rce
4 min readRead
Vulnerability Management27 July 2026
SharePoint RCE CVE-2026-50522: Patching Alone Won't Undo Stolen Machine Keys
A public PoC for a critical on-premises SharePoint deserialization flaw is being actively exploited within hours of release — and the payload attackers want isn't a shell, it's your machine keys.
sharepointcve-2026-50522rce
4 min readRead
Active Exploitation25 July 2026
Fastjson 1.x RCE (CVE-2026-16723) Is Under Active Attack — No Patch Yet
A critical, unauthenticated RCE in Alibaba's Fastjson 1.x is being exploited against Spring Boot fat-JAR deployments, and there is still no fixed 1.x release.
fastjsonrcejava
4 min readRead