Application Security

Application Security
ServiceNow Patches CVE-2026-6875 Unauthenticated RCE in AI Platform
ServiceNow patched CVE-2026-6875, a CVSS 9.5 unauthenticated remote code execution flaw in its AI platform; hosted instances auto-patched, self-hosted require manual update.
Application Security
CISA Adds Three SharePoint CVEs to KEV as Auth-to-RCE Chain
CISA added three SharePoint CVEs to its KEV catalog after confirming active attack chains combining auth bypass, code execution, and IIS machine key theft.
Application Security
Progress ShareFile Path Traversal Zero-Day Confirmed, Patches Out
Progress confirmed a path traversal zero-day in ShareFile SZC 5.x and 6.x after ordering an emergency shutdown. Patches 5.12.5 and 6.0.2 are now available.
Application Security
Unpatched Claude for Chrome Flaw Exposes Gmail and Calendar Data
Manifold disclosed two unpatched flaws in Claude for Chrome allowing malicious extensions to invoke the AI agent and silently access Gmail and Google Calendar.
Application Security
AsyncAPI npm Packages Backdoored to Deploy Miasma Botnet Loader
Four official AsyncAPI npm packages were compromised to deliver Miasma, a botnet loader using six C2 channels including Ethereum smart contracts and IPFS.
Application Security
CISA Adds Two CVSS 10.0 Joomla Extension Zero-Days to KEV
CISA added CVE-2026-48939 and CVE-2026-56291 to KEV with a same-day federal deadline after both Joomla extension zero-days were exploited before disclosure.
Application Security
Progress Orders ShareFile SZC Server Shutdown Over Security Threat
Progress Software ordered ShareFile Storage Zone Controller customers to shut down internet-facing servers amid an undisclosed security threat investigation.
Application Security
Ghostcommit PNG Attack Tricks AI Code Reviewers into Leaking .env
UMKC researchers demonstrated Ghostcommit, a PNG-based prompt injection attack that tricks AI code reviewers into exfiltrating .env secrets as code constants.
Application Security
Compromised jscrambler npm Package Drops Rust Infostealer on Devs
An attacker compromised jscrambler's npm credentials and published five malicious versions dropping a Rust infostealer targeting cloud and AI credentials.
Application Security
Google TAG Finds Critical Stored XSS in Zimbra Classic Web Client
Google's Threat Analysis Group found a critical stored XSS flaw in the Zimbra Classic Web Client that allows mailbox takeover via a single crafted email.