Multiple ServiceNow flaws are being linked together to attack companies and organizations

Hackers are linking multiple ServiceNow vulnerabilities to target companies and organizations, stealing user credentials.

Cybersecurity researchers at Resecurity discovered an input validation vulnerability that could allow threat actors to conduct remote code execution (RCE) attacks on multiple versions of the Now Platform. The vulnerability is now tracked as CVE-2024-4879 and has a severity score of 9.3.