This day 02:02 06:02 10:02 14:02 18:03 22:07
High  2026-08-28 14:02Z · last 4h · 22 findings · glm-5.2:cloud

Threat Brief — 2026-08-28 — Three CVSS 10.0s and a factory backdoor

ServiceNow has patched three maximum-severity vulnerabilities in its AI Platform, two of which can be exploited by unauthenticated attackers for code injection and SQL injection. cPanel disclosed a critical root-privilege escalation via domain parking, and Caddy's forward_auth mechanism was found vulnerable to identity header spoofing through CGI normalisation. Separately, ZBT routers shipping with factory-installed backdoors and the Unitree G1 EDU robot's Bluetooth-rootable attack surface highlight the widening exposure of edge and IoT hardware.

Top items

Themes

Unauthenticated critical paths dominate. Four of today's top items — ServiceNow, cPanel, Caddy, and the ZBT backdoors — expose root or code execution from an unauthenticated starting point, reinforcing that authentication boundaries remain the most frequently breached control.

Hardware supply chain trust gaps persist. ZBT's factory backdoors and Unitree's Bluetooth-rootable robot both illustrate that firmware and device-level defaults shipped by manufacturers can bypass perimeter controls entirely. Edge and IoT procurement should account for embedded functionality that cannot be remediated by patching alone.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db