ServiceNow has patched three maximum-severity vulnerabilities, including two leading to remote code execution.
The vulnerabilities can be exploited remotely without user interaction; security teams should also look beyond ServiceNow to the credentials, APIs and workflows the platform can access.