Skip to main content
Security

ServiceNow issues patches for three CVSS 10 code-injection flaws

ServiceNow issues patches for three CVSS 10 code-injection flaws Image: Primary
ServiceNow said it has deployed patches across hosted instances and released hotfixes for self-hosted deployments after disclosure of four vulnerabilities in its AI platform and Now Platform. Three flaws, rated CVSS 10, allow code execution, arbitrary data changes or arbitrary SQL statements in low-complexity attacks without authentication or user interaction. A fourth, rated 8.7, is a sandbox-escape issue that can enable code execution. The self-hosted hotfixes cover the Xanadu, Yokohama, Zurich and Australia releases.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from SecurityWeek and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Infrastructure
AI Infrastructure

VMware introduces private AI cloud platform for on-premises workloads

VMware and owner Broadcom introduced VMware Private AI Cloud and its AI Factory model-as-a-service offering at VMware Explore 2026. The platform builds on VMware Cloud Foundation 9 with validated AI-ready hardware nodes, support f...

Security AI
Security AI

Researchers link Aurora ransomware activity to Cursor AI agent use

CloudSEK and Gambit Security reported that operators associated with Aurora ransomware used Cursor's agentic coding tools while working against victim networks. Gambit said it observed Cursor Agent running Anthropic's Claude Sonne...

Security
Security

Berlin confirms extortion attempt after Rhysida data theft

Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after Rhysida listed it on a data-leak site. The attack was discovered in mid-August, according to the report, and affected Senate de...