View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

ServiceNow Faces Three CVSS 10.0 Unauthenticated Vulnerabilities

πŸ•΅οΈ RESEARCH & DEEP DIVES

πŸ”“ CVEs & KEV

  • CVE-2026-74820 β€” CVSS 10.0 β€” Unauthenticated SQL Injection via Dynamic Schema ORDER BY ClauseServiceNow ha...

  • CVE-2026-18886 β€” CVSS 10.0 β€” Unauthenticated Privilege Escalation via System Configuration Image Upload Pr...

  • CVE-2026-18885 β€” CVSS 10.0 β€” Unauthenticated Remote Code Execution in GraphQL Composite Data APIServiceNow...

  • CVE-2026-53579 β€” CVSS 9.3 β€” Trilium: Note Import to RCE via Book NoteTrilium is an open-source hierarchic...

  • CVE-2026-53578 β€” CVSS 9.3 β€” Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtmlTrilium is...

  • CVE-2026-81934 β€” CVSS 9.2 β€” Redis TLS pending-data list use-after-freeRedis contains a use-after-free vul...

  • CVE-2026-81730 β€” CVSS 8.8 β€” Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Fi...

  • CVE-2026-10036 β€” CVSS 8.7 β€” SpeechBrain before 1.1.1 Arbitrary Code Execution via CKPT.yaml ParsingSpeechBrain...

  • CVE-2026-6876 β€” CVSS 8.7 β€” Sandbox Escape in Now PlatformServiceNow has remediated a sandbox escape secu...

  • CVE-2026-76639 β€” CVSS 8.7 β€” Unitree G1 EDU Firmware RCE (CVE-2026-76639)

  • CVE-2026-81728 β€” CVSS 8.6 β€” Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update KeysD...

  • CVE-2026-53580 β€” CVSS 8.1 β€” Trilium arbitrary file read and denial of service via file:// URLs in the aut...

  • CVE-2026-77438 β€” CVSS 7.5 β€” Trilium unauthenticated share-search discloses password-protected and hidden ...

  • CVE-2026-81729 β€” CVSS 7.1 β€” Dolibarr before 23.0.4 Incorrect Authorization on REST API Document DeletionD...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check