🛡️ Cyber Times — CISO Intelligence Update
Friday, 28 August 2026 · Coverage: 27 Aug 2026 08:00 IST → 28 Aug 2026 08:00 IST
The high-confidence sweep produced 35 publishable records. This edition presents 7 source-linked updates across 1 security domains; 7 are marked for priority review.
🛡️ Vulnerabilities Worth Attention
CVE-2026-74820 — ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform
CRITICAL — NVD CVSS 10.0 (critical). ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance’s underlying database and gain access to, or modify, instance data beyond what was intended. ServiceNow deployed a security update to hosted…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 28 Aug 2026 01:48 IST Sources: NVD
CVE-2026-18886 — ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform
CRITICAL — NVD CVSS 10.0 (critical). ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 28 Aug 2026 01:47 IST Sources: NVD
CVE-2026-18885 — ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform
CRITICAL — NVD CVSS 10.0 (critical). ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended. ServiceNow deployed a security update to hosted instances and ServiceNow…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 28 Aug 2026 01:47 IST Sources: NVD
CVE-2026-81735 — startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to ’::’ when no host was given, so…
CRITICAL — NVD CVSS 10.0 (critical). startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to ’::’ when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a caller supplies them. The @agent-infra/mcp-server-commands and…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 27 Aug 2026 22:51 IST Sources: NVD
CVE-2026-19092 — The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated…
CRITICAL — NVD CVSS 9.8 (critical). The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 28 Aug 2026 01:47 IST Sources: NVD
CVE-2026-78292 — Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
CRITICAL — NVD CVSS 9.8 (critical). Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 27 Aug 2026 15:46 IST Sources: NVD
CVE-2026-78286 — Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
CRITICAL — NVD CVSS 9.8 (critical). Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 27 Aug 2026 15:46 IST Sources: NVD
💡 Defensive Priority
Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.
Collection: 2,885 records inspected · 134 passed collection filters · 35 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.