cybersecurityvulnerabilityServiceNowupdatecode execution

Critical ServiceNow code execution flaw now exploited in attacks

July 19, 2026

Back to all posts

Source: BleepingComputer

A critical vulnerability has been discovered in ServiceNow, a popular IT management software used by many Canadian businesses. The flaw, identified as CVE-2021-30633, allows an unauthenticated attacker to execute arbitrary code in ServiceNow instances using maliciously crafted XML data. This vulnerability, now being exploited in attacks, poses a significant risk for Canadian SMBs as it can lead to unauthorized access, data theft, and system disruption. To mitigate this threat, affected businesses are urged to immediately update their ServiceNow instances to the latest patched version (20.1.0-2021081803) or apply the available workaround. It's crucial for IT managers and business owners to stay vigilant and prioritize software updates to safeguard their systems and data.
cybersecurityvulnerabilityServiceNowupdatecode execution

Concerned about this threat to your business?

We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.

Book a free assessment