<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — ServiceNow</title><description>Vulnerabilities and exploitation targeting ServiceNow&apos;s platform and its AI Platform / Now Assist surfaces — a high-value enterprise SaaS foothold that frequently holds sensitive IT, HR, and workflow data across large organizations. Combined article + CVE feed for the ServiceNow beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2024-4879 — ServiceNow Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2024-4879/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-4879/</guid><description>ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely. </description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>ServiceNow</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-5217 — ServiceNow Incomplete List of Disallowed Inputs Vulnerability</title><link>https://0daynews.com/cve/cve-2024-5217/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-5217/</guid><description>ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>ServiceNow</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-6875 — ServiceNow AI Platform unauthenticated remote code execution</title><link>https://0daynews.com/cve/cve-2026-6875/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-6875/</guid><description>An unauthenticated attacker can, under certain circumstances, execute code on the ServiceNow AI Platform. Patched by ServiceNow on hosted instances; self-hosted customers and partners must apply the shipped updates.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>ServiceNow</category><category>critical</category><category>cve</category></item><item><title>ServiceNow Patches Three CVSS 10.0 Flaws in AI Platform</title><link>https://0daynews.com/articles/2026-08-29-servicenow-three-cvss10-ai-platform-flaws/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-29-servicenow-three-cvss10-ai-platform-flaws/</guid><description>ServiceNow patches three CVSS 10.0 AI Platform flaws. Self-hosted customers must update now; hosted instances were auto-patched August 28.</description><pubDate>Sat, 29 Aug 2026 00:30:00 GMT</pubDate><category>ServiceNow</category><category>article</category></item><item><title>ServiceNow AI Platform RCE exploited in wild: CVE-2026-6875</title><link>https://0daynews.com/articles/2026-07-20-servicenow-ai-platform-cve-2026-6875-defused-exploitation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-20-servicenow-ai-platform-cve-2026-6875-defused-exploitation/</guid><description>Threat-intel firm Defused reports active exploitation of ServiceNow AI Platform CVE-2026-6875, a week after ServiceNow said it saw none.</description><pubDate>Mon, 20 Jul 2026 10:30:00 GMT</pubDate><category>ServiceNow</category><category>article</category></item></channel></rss>