Skip to content
Threat Feed

Vendor

ServiceNow

6 briefs RSS
high advisory

Multiple Vulnerabilities in ServiceNow Now Platform and AI Platform

ServiceNow Now Platform and AI Platform are vulnerable to multiple flaws enabling arbitrary code execution, privilege escalation, and SQL injection, risking full environment compromise.

Now Platform +1 vulnerability service-now cloud-security informational
3t
medium advisory

City Forum Campaign Scraping Salesforce and ServiceNow Portals

A persistent threat actor is utilizing a single VPS infrastructure to perform unauthorized data scraping from Salesforce and ServiceNow guest portals by exploiting over-privileged guest account permissions.

Salesforce Experience Cloud +1
1r 1t 1i
high advisory

City-Forum Campaign Targeting Salesforce and ServiceNow Guest Access

An unidentified threat actor is leveraging a custom multi-platform toolset to exploit misconfigured guest user permissions in Salesforce and ServiceNow, performing high-volume data enumeration and exfiltration.

Salesforce Aura +2 data-exfiltration cloud-security reconnaissance guest-access-abuse
2t 2i
critical threat

CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core

CVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.

exploited PoC WordPress Core 6.9.0 +51 wordpress rce web-vulnerability cve
2t 15c 8i updated
high threat

ServiceNow Critical Sandbox Escape Vulnerability (CVE-2026-6875)

ServiceNow has released a security advisory addressing CVE-2026-6875, a critical sandbox escape vulnerability affecting multiple product versions including Brazil, Australia, Zurich, and Yokohama, which could allow an attacker to bypass security boundaries and execute arbitrary code with elevated privileges.

exploited Brazil +18 vulnerability servicenow cloud
3c updated
high advisory

Remote Code Execution Vulnerability in ServiceNow AI Platform

A remote, anonymous attacker can exploit a vulnerability in ServiceNow AI Platform to execute arbitrary program code, leading to unauthorized control over the platform's underlying systems.

ServiceNow AI Platform vulnerability rce cloud-security
2t