CyberHighSingle-sourceDeveloping
7.8
Active exploitation of PaperCut vulnerabilities enables unauthenticated remote code execution
The Hacker News·3 days ago
ServiceNow has disclosed three vulnerabilities with a maximum CVSS score of 10.0, allowing for unauthenticated arbitrary code execution, privilege escalation, and SQL injection. While the vendor reports no evidence of active exploitation, the severity and lack of authentication requirements present a high risk for enterprise infrastructure.