AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 01 Sept, 08:10

ServiceNow discloses three CVSS 10.0 flaws letting unauthenticated attackers run code and query databases

ServiceNow disclosed four vulnerabilities in its AI Platform on August 27, three of them rated the maximum severity score of 10 out of 10. No login or user interaction is needed to exploit them. ServiceNow says it hasn't seen exploitation so far, but patches are available now.

ServiceNow disclosed four vulnerabilities across its AI Platform and Now Platform on August 27, 2026. Three scored a perfect 10.0: a code injection flaw in the GraphQL Composite Data API, an access control failure in the system configuration image upload processor, and a SQL injection flaw in a database ordering function. A fourth, rated 8.7, allows a scripting sandbox escape. All three top flaws are exploitable over the network with no authentication and no user interaction. ServiceNow says it hasn't seen exploitation yet and has patched its own hosted instances, but self-hosted and partner-managed customers must apply the fix themselves. A related flaw disclosed in July was targeted by scanning activity within weeks of going public.

#cyber
Published on