ServiceNow
Vulnerabilities and exploitation targeting ServiceNow's platform and its AI Platform / Now Assist surfaces — a high-value enterprise SaaS foothold that frequently holds sensitive IT, HR, and workflow data across large organizations.
ServiceNow AI Platform unauthenticated remote code execution
An unauthenticated attacker can, under certain circumstances, execute code on the ServiceNow AI Platform. Patched by ServiceNow on hosted instances; self-hosted customers and partners must apply the shipped updates.
ServiceNow Improper Input Validation Vulnerability
ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely.
ServiceNow Incomplete List of Disallowed Inputs Vulnerability
ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely.

ServiceNow Patches Three CVSS 10.0 Flaws in AI Platform
ServiceNow patches three CVSS 10.0 AI Platform flaws. Self-hosted customers must update now; hosted instances were auto-patched August 28.

ServiceNow AI Platform RCE exploited in wild: CVE-2026-6875
Threat-intel firm Defused reports active exploitation of ServiceNow AI Platform CVE-2026-6875, a week after ServiceNow said it saw none.