ServiceNow patches three maximum-severity AI Platform flaws

Hands typing on a laptop displaying data charts in an indoor setting.

ServiceNow released security updates for its cloud-based workflow automation platform to address three newly disclosed maximum-severity AI Platform vulnerabilities, according to a Thursday advisory cited in cybersecurity coverage on August 31. The flaws, tracked as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, can be exploited in code injection, SQL injection, and privilege escalation attacks, and the company urged customers with self-hosted instances to apply the fixes and secure those deployments.

PaperCut zero-day under active exploitation across NG and MF

Print management vendor PaperCut warned customers on August 31 that threat actors are exploiting a previously unknown vulnerability affecting all versions of PaperCut NG and PaperCut MF in zero-day attacks. The vendor pushed an emergency patch covering versions 25 and 26, while leaving details of the flaw, exploitation method, and attribution undisclosed. Operators running PaperCut NG/MF Application Servers exposed to the internet were told to immediately restrict access to trusted IP addresses until patching is complete.

McKesson discloses breach; ShinyHunters claims 284 million patient records

Major U.S. pharmaceutical distributor McKesson confirmed a cybersecurity incident involving unauthorized access to third-party applications and subsequent data theft, with the company saying it discovered the intrusion on August 25. The ShinyHunters extortion group publicly claimed responsibility for the attack and asserted that it stole 284 million patient data records, a figure that has not yet been independently verified. McKesson said it provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies and is notifying affected parties as the investigation continues.

TerminalFix campaign spoofs Cloudflare CAPTCHAs to seed malware

Microsoft researchers reported a new ClickFix variant dubbed TerminalFix that lures victims into running malicious commands inside Windows Terminal or PowerShell rather than the traditional Run dialog, increasing the chance that complex multi-line scripts execute successfully. The campaign begins on compromised websites that serve fake Cloudflare CAPTCHA verifications and is hitting organizations across multiple sectors. Defenders are advised to monitor for unusual Windows Terminal and PowerShell invocations originating from browser-driven user actions.

Coordinated disclosure pressure on healthcare and enterprise vendors

The simultaneous appearance of a McKesson breach, a PaperCut zero-day with no public technical details, and a trio of maximum-severity ServiceNow flaws illustrates the disclosure load facing healthcare and enterprise software operators in a single news cycle. Customers of each vendor must reconcile emergency patching on PaperCut NG/MF and self-hosted ServiceNow instances with forensic review of third-party application access paths following the McKesson incident. The unresolved questions are concrete: which PaperCut build fully addresses the flaw, how many McKesson records were actually exfiltrated, and whether the ServiceNow vulnerabilities have been observed in active exploitation.

Next verifiable milestones

Operators should track PaperCut's forthcoming technical advisory on the NG/MF flaw, ServiceNow's confirmation that self-hosted customer instances have applied the AI Platform patches, and McKesson's next update on the scope of the third-party application breach and any regulatory notifications. Subsequent reporting from BleepingComputer and The Hacker News is expected to provide technical details on the PaperCut exploit and attribution signals around the McKesson intrusion.

Share this article

FacebookX

2 sources

Sources