CVE-2026-6875 is a remote code execution vulnerability identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers an [truncated]
CVE-2024-5217 is a ServiceNow Now Platform issue affecting Utah, Vancouver, and Washington DC releases and described as an incomplete list of disallowed inputs vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-29, which makes it a high-priority defensive item for organizations running the affected platform versions.
CVE-2024-4879 is a ServiceNow Now Platform improper input validation issue that CISA added to its Known Exploited Vulnerabilities catalog on 2024-07-29. The supplied corpus identifies ServiceNow Utah, Vancouver, and Washington DC Now Platform as the affected product scope. Because it is in the KEV catalog, defenders should treat it as a high-priority remediation item and follow vendor guidance promptly.