CVE Tools

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Help Net SecurityBy Help Net Security

Reported exploitedSalesforceServiceNow

Our summary

A long-running campaign dubbed City-Forum has been extracting data from Salesforce and ServiceNow portals globally for 17 months without triggering traditional breach alerts. Meanwhile, Framework confirmed a data breach stemming from an exploited zero-day vulnerability in the Metabase business intelligence platform.

N-able released a second hotfix for N-central to counter active exploitation of CVE-2026-18577, while Cisco addressed CVE-2026-20349, a high-severity flaw currently being used to disrupt firewall operations.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store