CuraSec

Plan active

ServiceNow Patches Three CVSS 10.0 Flaws Allowing Unauth RCE and SQLi

2026-08-28 21:21 UTC · The Hacker News · read the source ↗ #servicenow#rce#critical-vulnerability
  • Engineer — Plan: Three unauthenticated RCE/SQLi flaws at maximum severity demand prompt action, but no KEV listing or public PoC elevates this to Act yet. If running self-hosted ServiceNow, apply the patch this week and verify hosted instances received the automated update.
  • SOC/IR — Skip
  • Leader — Plan: Three CVSS 10.0 flaws in a widely deployed ITSM platform warrant confirming whether your organization runs self-hosted ServiceNow and ensuring the patch was applied; hosted tenants should receive confirmation from ServiceNow that their instances were updated.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.