logo

ServiceNow Remote Code Execution Attack

ID: 03b5c69f-1372-5456-a30f-5e24bca2d888

STIX ID: report--03b5c69f-1372-5456-a30f-5e24bca2d888

Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts

Threat Score
75/100

Date Published: 2024-08-06

Date Updated: 2026-07-28

...
...

FortiGuard Labs reports active attack attempts against three ServiceNow Now Platform vulnerabilities (CVE-2024-4879, CVE-2024-5178, CVE-2024-5217) — including Jelly Template Injection and incomplete input validation bugs that can enable remote code execution and unauthorized access. The flaws affect multiple Now Platform releases, are reportedly being targeted in the wild with potential PoC weaponization, and organizations using ServiceNow are advised to apply the vendor updates immediately to mitigate potential data breaches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.