VYPR
AI Brief2026-08-30· generated Aug 30, 2026

Critical Flaws in ServiceNow, Ubiquiti, IBM, WordPress Patched

Critical vulnerabilities patched in ServiceNow, Ubiquiti, IBM, and WordPress plugins, enabling code execution and authentication bypass.

ServiceNow has addressed three critical vulnerabilities in its AI platform, including SQL injection (CVE-2026-74820), improper access control (CVE-2026-18886), and code injection (CVE-2026-18885). These flaws could allow unauthenticated attackers to execute arbitrary SQL statements, modify instance data, or run arbitrary code, posing a significant risk to sensitive information and system integrity. The vendor has released patches to remediate these issues, and users are urged to update immediately.

Ubiquiti's UniFi OS and associated applications are affected by several critical vulnerabilities, including command injection in UniFi Talk and Protect applications (CVE-2026-77554, CVE-2026-77537) and an authentication bypass in UniFi OS due to improper CRLF sequence neutralization (CVE-2026-77550). These flaws, some with CVSS scores of 10.0, could allow network-accessible attackers to execute arbitrary commands on the host device or gain unauthorized access to UniFi OS instances. Patches are available for these issues.

IBM has disclosed multiple vulnerabilities across its product lines, with critical flaws impacting Langflow OSS versions 1.0.0 through 1.11.1. These include arbitrary operating system command execution via crafted flow saves (CVE-2026-19295) and arbitrary code execution due to improper security restrictions on the A2A public endpoint (CVE-2026-19286). Additionally, IBM Administration Runtime Expert for i is affected by a vulnerability allowing privilege escalation (CVE-2026-18527). IBM has released fixes for these vulnerabilities.

Several WordPress plugins are impacted by critical vulnerabilities. The Sigma Forms Pro plugin (up to 1.4.5) suffers from Remote Code Execution due to improper handling of file uploads (CVE-2026-14494). The WPMU DEV Dashboard plugin (up to 5.0.1) has an authentication bypass vulnerability (CVE-2026-76581). These flaws could lead to complete site compromise if exploited. Developers have released updates to address these security weaknesses.

Microsoft has patched a critical Server-Side Request Forgery (SSRF) vulnerability in Azure SQL Database (CVE-2026-69502) that could allow unauthorized attackers to elevate privileges over a network. Additionally, Siemens has addressed a vulnerability in SIMATIC IoT2050 Advanced devices (CVE-2026-58115) where unpatched Node-RED interfaces allow unauthenticated access. These vulnerabilities highlight the ongoing risks in cloud infrastructure and industrial control systems.

Synthesized by Vypr AI
Critical Flaws in ServiceNow, Ubiquiti, IBM, WordPress Patched · VYPR