cybersecurityvulnerabilityServiceNowupdatecode execution
Critical ServiceNow code execution flaw now exploited in attacks
July 19, 2026
Back to all postsA critical vulnerability has been discovered in ServiceNow, a popular IT management software used by many Canadian businesses. The flaw, identified as CVE-2021-30633, allows an unauthenticated attacker to execute arbitrary code in ServiceNow instances using maliciously crafted XML data. This vulnerability, now being exploited in attacks, poses a significant risk for Canadian SMBs as it can lead to unauthorized access, data theft, and system disruption. To mitigate this threat, affected businesses are urged to immediately update their ServiceNow instances to the latest patched version (20.1.0-2021081803) or apply the available workaround. It's crucial for IT managers and business owners to stay vigilant and prioritize software updates to safeguard their systems and data.
Source: BleepingComputer
cybersecurityvulnerabilityServiceNowupdatecode execution
Concerned about this threat to your business?
We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.
