Major tech players Fortinet, Ivanti, and ServiceNow have released urgent security patches to address critical flaws, including a high-risk RCE in ServiceNow's AI platform.
Key Takeaways
- ServiceNow patched a critical Remote Code Execution (RCE) flaw (CVE-2026-6875) in its AI platform.
- Fortinet addressed 12 vulnerabilities across multiple products, including FortiOS and FortiSandbox.
- Ivanti fixed path traversal and open redirect flaws in its Xtraction tool.
- No evidence of active exploitation in the wild has been reported by the vendors.
In a significant move to bolster digital defenses, industry giants Fortinet, Ivanti, and ServiceNow rolled out essential security patches on Tuesday to mitigate a series of vulnerabilities across their product ecosystems. The updates target a range of issues, from medium-severity redirects to critical-level code execution flaws that could compromise enterprise integrity.
The ServiceNow AI Risk
The most alarming discovery involves the ServiceNow AI platform. The company addressed a critical Remote Code Execution (RCE) vulnerability, tracked as CVE-2026-6875, which boasts a staggering CVSS score of 9.5. This vulnerability is particularly dangerous because it could allow unauthenticated remote attackers to execute arbitrary code on affected systems. ServiceNow has already deployed security updates to its hosted instances and has provided necessary guidance to self-hosted customers and partners to prevent unauthorized access.
Fortinet's Extensive Patch Rollout
Fortinet took a broader approach, publishing 11 security advisories covering 12 distinct vulnerabilities. These flaws impact a wide array of its flagship products, including FortiOS, FortiProxy, FortiSASE, and FortiSandbox. The most severe bugs were identified in FortiAuthenticator and FortiSandbox, where unauthenticated attackers could potentially retrieve sensitive data or gain access to the VNC servers of virtual machines. Additionally, the patches resolve various issues related to memory leaks, command execution, and authentication request interception.
Ivanti's Xtraction Fixes
Ivanti focused on its data aggregation and visualization tool, Xtraction, releasing fixes for two specific defects: CVE-2026-14902 and CVE-2026-14903. These vulnerabilities included a medium-severity open redirect and a high-severity path traversal. If left unpatched, these flaws could allow malicious actors to redirect unsuspecting users to fraudulent URLs or read sensitive files located outside the web root directory.
Industry Implications
While all three companies emphasized that there is currently no known evidence of these vulnerabilities being exploited in the wild, the severity of the ServiceNow flaw serves as a stark warning. As enterprises increasingly integrate Artificial Intelligence into their core workflows, the attack surface expands exponentially. Cybersecurity experts urge organizations to adopt a proactive patching posture to defend against the looming threat of zero-day exploits that target these newly discovered weaknesses.