CyberHighConfirmedDeveloping
9.3
Unpatched Kaltura mwEmbed vulnerabilities enable unauthenticated RCE and file exposure
The Hacker News·2 days ago
ServiceNow has disclosed three vulnerabilities with a maximum CVSS score of 10.0, allowing for unauthenticated arbitrary code execution, privilege escalation, and SQL injection. While the vendor reports no evidence of active exploitation, the severity and lack of authentication requirements present a high risk for enterprise infrastructure.