ServiceNow Patches 3 Critical Code Injection Vulnerabilities
Attackers could exploit the security defects to execute arbitrary code and access or tamper with data. The post ServiceNow Patches 3 Critical Code Injection Vulnerabilities appeared first on SecurityWeek.
ServiceNow has announced patches for four vulnerabilities, including three critical code injection flaws in the ServiceNow AI platform, each with a maximum severity (CVSS score of 10/10).
The first of the critical bugs, tracked as CVE-2026-18885, allows an attacker to execute arbitrary code in the ServiceNow platform under certain circumstances.
An attacker could exploit the weakness to gain access to and potentially modify arbitrary data, ServiceNow notes in its advisory.
Source: https://www.securityweek.com/servicenow-patches-3-critical-code-injection-vulnerabilities/
Related breach coverage
- WatchGuard Patches Critical Vulnerabilities2026-09-01
Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely. The post WatchGuard Patches Critical Vulnerabilities appeared first on SecurityWeek.
- Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities2026-08-20
The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek.
- ISC Patches 14 Vulnerabilities in BIND 9 Security Update2026-09-17
Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek.
- Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution2026-09-14
The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely. The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution appeared first on SecurityWeek.