3Corns

Fortinet, Ivanti, ServiceNow Issue Patches for Security Vulnerabilities

A critical vulnerability in ServiceNow's AI platform could be exploited by remote attackers to run arbitrary code.

This week saw three major vendors — Fortinet, Ivanti, and ServiceNow — collectively address 15 security flaws across their respective product lines.

Among the fixes, ServiceNow tackled a critical, unauthenticated remote code execution bug in its AI platform, identified as CVE-2026-6875 and carrying a steep CVSS rating of 9.5. According to the company, the issue has already been resolved on hosted instances via a security update, with corresponding patches made available to self-hosted customers and partner organizations as well.

Separately, Ivanti pushed out fixes for a pair of flaws in Xtraction, its tool for aggregating and visualizing data — tracked under CVE-2026-14902 and CVE-2026-14903. One is a medium-severity open redirect issue, while the other is a high-severity path traversal bug; together, they could have let an attacker send victims to malicious external sites or pull files from outside the intended web directory.

Both ServiceNow and Ivanti indicated they've seen no evidence so far that these bugs have been exploited in real-world attacks.

Meanwhile, Fortinet issued 11 separate advisories on Tuesday covering a dozen vulnerabilities spread across several of its products — including FortiOS, FortiProxy, FortiSASE, FortiSIEM, FortiClient EMS, FortiAuthenticator, FortiPAM, FortiSwitch Manager, FortiSwitch-Manager Agentless SSL-VPN, and FortiSandbox.

The most serious among them are high-severity issues affecting FortiAuthenticator and FortiSandbox, which unauthenticated remote attackers could potentially leverage to pull sensitive data or gain access to the VNC server tied to virtual machines used for scanning tasks.

Beyond those, Fortinet's update batch also covers a range of medium- and low-severity problems, including memory leaks, the ability to execute commands, injection of arbitrary headers, interception or tampering with authentication traffic, impersonation of an AD Connector through a stolen API key, deletion of file system data, and additional code execution risks.

Fortinet did not indicate that any of these vulnerabilities have been observed being exploited in active attacks.