← Global Threat Landscape

CVE-2024-4879

CWE-1287

Critical

103.8

RPS

Description

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

Source: NVD

Signals

CVSS
9.8
Critical · v3.1
EPSS
99.97%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Jul 2024
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-1287
Published
10 Jul 2024
Last modified 3 Nov 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2024-4879

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2024-4879 · RPS 103.8 · DevSecure Intelligence