Threat Brief — 2026-08-28 — Three CVSS 10.0s and a factory backdoor
ServiceNow has patched three maximum-severity vulnerabilities in its AI Platform, two of which can be exploited by unauthenticated attackers for code injection and SQL injection. cPanel disclosed a critical root-privilege escalation via domain parking, and Caddy's forward_auth mechanism was found vulnerable to identity header spoofing through CGI normalisation. Separately, ZBT routers shipping with factory-installed backdoors and the Unitree G1 EDU robot's Bluetooth-rootable attack surface highlight the widening exposure of edge and IoT hardware.
Top items
- ServiceNow AI Platform — three CVSS 10.0 vulnerabilities patched. The flaws allow unauthenticated code injection, SQL injection, and privilege escalation under certain configurations. Patches are available; exploitation prerequisites remain under analysis. (src: The Hacker News, BleepingComputer)
- cPanel — root code execution via domain parking flaw. A vulnerability in cPanel/WHM's domain parking and addon domain functionality could let a hosting customer execute code as root. Patches have been released. (src: The Hacker News)
- Caddy < 2.11.4 — forward_auth identity header spoofing (CVE-2026-52845). The
copy_headersdirective deletes the client-supplied identity header before copying the trusted value from the auth gateway, butphp_fastcginormalises HTTP headers by replacing hyphens with underscores, enabling an attacker to inject a spoofed identity header that survives deletion. (src: NVD)
- Unitree G1 EDU humanoid robot — two root RCE chains disclosed. Researcher Olivier Laflamme demonstrated two independent root remote code execution paths, one of which originates over Bluetooth Low Energy and reaches root on the robot's Locomotion PC. (src: The Hacker News)
- ZBT routers ship with two factory backdoors. VulnCheck disclosed two previously undocumented firmware implants in routers built by Shenzhen Zhibotong Electronics (ZBT), one granting unauthenticated root command execution and the other capable of credential theft and DNS manipulation. (src: The Hacker News, SecurityLab.ru)
- Nuclear archives compromised via ownCloud vulnerability. A single flaw gave attackers access to ultra-sensitive nuclear-sector data; the full scope and long-term implications are still being assessed. (src: SecurityLab.ru)
- Hasbro discloses employee data breach. Attackers accessed personal and financial information of an undisclosed number of employees at the toy and game company. (src: BleepingComputer)
- Hachette Australia cyberattack disrupts nationwide book deliveries. Australia's largest book distributor cannot give a full recovery date; deliveries remain manually managed after a single attack disrupted operations. (src: SecurityLab.ru)
- AI-powered vulnerability reports are depressing bug bounty payouts. A surge in AI-generated submissions is driving down reward prices, raising concerns about sustainability for independent researchers. (src: Dark Reading)
Themes
Unauthenticated critical paths dominate. Four of today's top items — ServiceNow, cPanel, Caddy, and the ZBT backdoors — expose root or code execution from an unauthenticated starting point, reinforcing that authentication boundaries remain the most frequently breached control.
Hardware supply chain trust gaps persist. ZBT's factory backdoors and Unitree's Bluetooth-rootable robot both illustrate that firmware and device-level defaults shipped by manufacturers can bypass perimeter controls entirely. Edge and IoT procurement should account for embedded functionality that cannot be remediated by patching alone.
