logo

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

ID: f3545a5f-f64e-5258-8742-8241a78849de

STIX ID: report--f3545a5f-f64e-5258-8742-8241a78849de

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

Author: [email protected] (The Hacker News)

...
...

ServiceNow published patches for four critical vulnerabilities in its Now Platform/AI Platform—three rated CVSS 10.0 (GraphQL code injection, image-upload access control leading to privilege escalation, and a SQL injection via ORDER BY) and one sandbox escape (8.7). Hosted instances have been updated by ServiceNow, while self-hosted customers must apply the fixes; ServiceNow reports no observed exploitation of these four issues, although a previously disclosed sandbox escape had reported exploitation activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.