#5
The Hacker News
general
August 28, 2026 at 11:20 UTC
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
By [email protected] (The Hacker News)
AI Summary
ServiceNow patched four vulnerabilities in its AI Platform, three rated CVSS 10.0, enabling unauthenticated attackers to perform code injection, SQL injection, and privilege escalation under certain conditions. The company deployed fixes to hosted instances and issued updates to partners and self-hosted customers, but organizations running self-hosted deployments must manually apply patches. Given the maximum severity rating and the broad enterprise deployment of ServiceNow, this warrants immediate patching priority.
Relevance score: 84.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →