IT News Roundup: ServiceNow and WordPress Vulnerabilities, NVIDIA Vera CPU, EU vs. Google - July 23, 2026
This week in IT: critical RCE vulnerabilities hit ServiceNow and WordPress with CISA deadlines, NVIDIA unveils its Vera CPU for agentic AI, the EU orders Google to open Android to AI rivals, and Oracle slashes 30,000 jobs to fund its Stargate AI ambitions.
This week in IT, security teams are scrambling to patch two critical remote code execution vulnerabilities affecting ServiceNow and WordPress, both of which are already being exploited in the wild with CISA patch deadlines looming. Meanwhile, NVIDIA has officially launched its purpose-built Vera CPU for agentic AI workloads, and the European Union has issued binding orders forcing Google to open Android and Search data to AI competitors. In industry news, Oracle has completed a sweeping round of 30,000 layoffs to redirect billions toward its Stargate AI data center project.
Critical ServiceNow RCE Vulnerability (CVE-2026-6875) Actively Exploited in the Wild
A critical unauthenticated remote code execution vulnerability in the ServiceNow AI platform, tracked as CVE-2026-6875, is now being actively exploited in targeted attacks. The flaw allows attackers to escape ServiceNow's script sandbox and execute arbitrary code remotely on affected instances.
Security researchers at Searchlight Cyber disclosed the vulnerability, which involves a code injection attack chain of high complexity. Exploitation was observed just days after disclosure, underscoring the urgency for organizations running ServiceNow to apply patches immediately. The vulnerability affects the core platform used by thousands of enterprises for IT service management, HR workflows, and security operations.
Source: BleepingComputer | SecurityWeek
WordPress wp2shell Vulnerabilities (CVE-2026-63030 and CVE-2026-60137) โ CISA Patch Deadline July 24
Two critical vulnerabilities in WordPress Core, collectively dubbed wp2shell, have been added to CISA's Known Exploited Vulnerabilities Catalog. CVE-2026-63030 is a REST API batch-route confusion vulnerability that can be chained with CVE-2026-60137, a SQL injection flaw, to achieve full remote code execution on default WordPress installations โ no additional plugins required.
CISA has set a patch compliance deadline of July 24, 2026, meaning administrators have less than 48 hours to update their installations. The vulnerabilities carry a CVSS score of up to 9.8 and are already being weaponized in active campaigns. WordPress powers roughly 43% of all websites globally, making this one of the most impactful web platform vulnerabilities of 2026.
Source: Rapid7 | Qualys ThreatPROTECT
NVIDIA Launches Vera CPU โ Purpose-Built for Agentic AI and Reinforcement Learning
NVIDIA has officially launched the Vera CPU, described as the world's first processor purpose-built for the age of agentic AI. Based on a custom Arm microarchitecture codenamed "Olympus," Vera is designed to deliver twice the efficiency and 50% faster performance compared to traditional rack-scale CPUs for AI agent workloads.
The chip is now in full production and has already been adopted by AI innovators including Perplexity. NVIDIA claims Vera enables 1.8x faster task completion compared with x86 CPUs across agentic AI, reinforcement learning, and data processing workloads. The launch signals NVIDIA's deepening move beyond GPUs into the broader server CPU market, directly challenging AMD and Intel in data center infrastructure.
Source: NVIDIA Newsroom | CNBC
EU Orders Google to Open Android and Search Data to AI Competitors Under DMA
The European Commission has issued two binding Digital Markets Act decisions requiring Google to open parts of Android and Google Search to competing AI services. Under the ruling, Google must allow rival search engines and AI assistants comparable access to Android's AI features by next July, and begin sharing anonymized search engine data with competitors by January 2027.
The decisions include privacy and security safeguards designed to protect user data while creating interoperability opportunities for AI chatbot makers and alternative search providers. The ruling represents one of the most significant regulatory actions against Big Tech under the DMA and could reshape how AI services integrate with mobile platforms across the European market.
Oracle Completes 30,000 Layoffs to Fund $50 Billion Stargate AI Investment
Oracle has completed a sweeping workforce reduction of approximately 30,000 positions as part of a strategic pivot toward AI infrastructure. The layoffs are the primary lever Oracle is using to preserve free cash flow while servicing $134.6 billion in total debt and funding an estimated $50 billion in FY26 capital expenditure on NVIDIA and AMD GPUs.
The redirected funding supports Oracle's role in the Stargate initiative โ a $300 billion, five-year compute contract with OpenAI for AI data center construction. Oracle plans to redirect $8 to $10 billion in annual cash flow toward the project. The move has drawn attention for its scale and the aggressive bet on AI infrastructure over traditional enterprise software operations.
Source: Tech Insider
Windmill Open-Source Platform Hit by Actively Exploited Path Traversal (CVE-2026-29059)
Windmill, an open-source developer platform for building internal tools, APIs, workflows, and UIs, has been hit by a critical path traversal vulnerability tracked as CVE-2026-29059 (CVSS 7.5). The flaw affects the get_log_file endpoint and allows unauthenticated attackers to read arbitrary files from the server.
Active exploitation has already been observed in the wild. Windmill has seen growing adoption among development teams for automating internal processes, making this vulnerability particularly concerning for organizations that have deployed self-hosted instances. Users are urged to upgrade to patched versions immediately and audit exposed endpoints.
Source: The Hacker News | SentinelOne
โ Back to Blog