ServiceNow has issued an urgent security advisory regarding three critical vulnerabilities affecting its platform releases, including Washington DC, Vancouver, and Utah. The most severe of these flaws, tracked as CVE-2024-4835 and CVE-2024-4836, have been assigned a maximum CVSS score of 10.0. These vulnerabilities stem from improper input validation within the Jelly template engine, potentially allowing unauthenticated attackers to perform remote code execution (RCE) on the server.
Administrators are strongly encouraged to apply the latest patches and hotfixes provided by ServiceNow immediately. Because the platform often manages sensitive enterprise data and critical workflows, these unauthenticated RCE vulnerabilities represent a significant risk to organizational security. Although there is currently no evidence of active exploitation, the severity of these bugs makes them high-priority targets for threat actors.
Top comments (0)