Summary
ServiceNow released emergency patches for three critical vulnerabilities (CVSS 10.0) and one high-severity flaw in its AI Platform that allow unauthenticated remote code execution and SQL injection. These flaws put sensitive enterprise data and connected corporate systems at risk of full takeover.
Take Action:
If you self-host ServiceNow, apply the vendor patches ASAP: Xanadu Patch 11, Yokohama Patch 12/13, or Zurich Patch 7-12. Cloud-hosted instances are already fixed. Then check your logs for unusual GraphQL requests or unexpected admin account changes. If possible limit which ServiceNow interfaces are reachable from the internet.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)