ServiceNow has patched three maximum-severity vulnerabilities, including two leading to remote code execution.
Update 6/10/26: Added details below from a new ServiceNow advisory regarding the observed activity and bug bounty submissions. ServiceNow is warning about a security incident after attackers exploited ...
The vulnerabilities can be exploited remotely without user interaction; security teams should also look beyond ServiceNow to ...