Home / Aug 29, 2026 / Story
0
#5 The Hacker News general August 28, 2026 at 11:20 UTC

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

By [email protected] (The Hacker News)

AI Summary

ServiceNow patched four vulnerabilities in its AI Platform, three rated CVSS 10.0, enabling unauthenticated attackers to perform code injection, SQL injection, and privilege escalation under certain conditions. The company deployed fixes to hosted instances and issued updates to partners and self-hosted customers, but organizations running self-hosted deployments must manually apply patches. Given the maximum severity rating and the broad enterprise deployment of ServiceNow, this warrants immediate patching priority.

Relevance score: 84.0/100

# More from August 29