ServiceNow Patches Three Maximum-Severity Flaws as Security Roundup Highlights Router Malware and Freezer Concerns
ServiceNow fixed three CVSS-10 vulnerabilities affecting hosted and on-premises instances. The weekly security roundup also covers embedded router malware, a Qubes OS file-copy flaw, possible freezer control issues at US military commissaries, and a BGP hijack targeting Virtualizor.
ServiceNow, the enterprise software platform used by major corporations, has released patches for three vulnerabilities rated at the maximum severity level of 10 on the CVSS scale. The flaws affect both the company's hosted cloud instances and its on-premises deployments. According to the advisory, one vulnerability allowed unauthenticated modification of data in hosted environments, another permitted arbitrary code execution through the GraphQL interface, and the third enabled attackers to run arbitrary SQL commands that could alter the underlying database. ServiceNow counts Adobe, Lenovo, FedEx, and Fujitsu among its high-profile customers, making the rapid deployment of these patches a priority for security teams across multiple industries.
In a separate development, the National Vulnerability Database reported embedded malware in routers sold under the Zbtlink and MoreQuick brand names. Multiple firmware versions across several product lines contain a backdoor service that communicates with a command-and-control server using unencrypted UDP traffic. Because the traffic is not encrypted, anyone who can intercept the network connection can also issue commands to the device. The backdoor executes commands with root privileges, giving attackers the ability to change configurations, open tunnels, or steal ISP credentials. The malware is baked directly into the firmware, meaning a factory reset will not remove it. For users with compatible hardware, installing third-party firmware such as OpenWRT may offer a path to a safer device, though the practice of marketing the same hardware under dozens of different brand names suggests the affected firmware may exist in other products that have not yet been identified.
The security-focused operating system Qubes OS also issued a bulletin addressing a vulnerability in its file-copy utility. The tool, qvm-copy-to-vm, displays an error message when a file transfer fails, but it does so by launching the kdialog application with the error text passed as arguments. The underlying system call interprets the error content as shell commands, meaning a crafted error message could escape its intended context and execute arbitrary commands on the system. Qubes has already prepared a fix, and users who receive standard updates should have the patch available for installation.
Separately, independent researchers have been tracking reports that freezer units in commissaries at US military bases have been malfunctioning. Posts on Reddit and coverage by Stars and Stripes indicate that at least fourteen bases across the country have experienced issues. Staff members clarified that the problem was not a loss of power or cooling capacity, but rather that the units were entering defrost mode and heating themselves. The Defense Commissary Agency operates these facilities with central monitoring and control systems. Researchers have pointed to published vulnerabilities in Danfoss and Copeland refrigeration controllers that could allow unauthorized access and full control of unit settings. While the researchers acknowledge that confirmation from the commissary agency is still needed, the pattern of failures combined with known controller vulnerabilities has raised concerns about a possible coordinated intrusion.
Finally, the web hosting management platform Virtualizor was the target of a global routing attack. The attackers hijacked the Border Gateway Protocol route for a small block of IP addresses used by Virtualizor and combined that with spoofed SSL certificates to push fraudulent software updates to users. BGP, the protocol that directs traffic across the internet, operates on a trust model without built-in authentication or encryption, making it vulnerable to this type of manipulation. The attack targeted a relatively small allocation of 253 addresses, but the combination of route hijacking and certificate spoofing demonstrates a sophisticated approach to compromising software supply chains.



