DeepGuards published three ServiceNow CVSS 10.0 findings that could allow unauthenticated code execution and SQL access.
Public source
Publisher name
Public post
Three CVSS 10.0 findings in a platform are a board-level patching event, not a ticket for next sprint. Researchers disclosed three ServiceNow flaws that could allow unau…
Company
DeepGuards
Penetration testing & security assessment: Web, API, Android, iOS, Cloud, AI Agents & MCP, Attack surface, Darkweb leaks
- Industry
- Computer and Network Security
- Location
- London, GB
- Company size
- 1 employee
About DeepGuards
DeepGuards is a UK-based cybersecurity firm offering penetration testing and security assessments for Web, API, mobile, cloud, and AI agents. Trusted for SOC 2, ISO 27001, and PCI-DSS engagements, they reveal hidden vulnerabilities and provide actionable remediation to prevent breaches.
See moreLatest activity
Latest activity from DeepGuards
4 signals
Research & Knowledge
DeepGuards uncovered 1,230 hidden subdomains and open ports, plus 43 unprotected development environments.
Research & Knowledge
DeepGuards includes dark web credential intelligence and account takeover checks alongside AppSec-led penetration testing, mitigating 24,000+ dark web leaks and identifying 32 critical account takeover gaps.
Research & Knowledge
DeepGuards tests the paths attackers use after a single bad click, including endpoint controls and internal access.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
Telefónica Tech (EN)
Telefónica Tech (EN) reported that ServiceNow patches three vulnerabilities with a CVSS score of 10.0 that allow code execution and SQL injection without authentication.
Research & Knowledge
VulnCheck
VulnCheck published an in-depth analysis of vulnerabilities affecting Langflow, a popular open source, low-code platform for building and deploying AI agents and workflows, including 11 additional Langflow CVEs reported in 2026.
Research & Knowledge
NightVision
NightVision reported three separate CVEs landed in CISA's Known Exploited Vulnerabilities list this quarter, from three unrelated products, with the same root cause of an admin or config endpoint that should have required a login and didn't.
Research & Knowledge
Empirical Security
Empirical Security published CVE-2026-58138, a 9.8 CVSS vulnerability affecting Netflix's Conductor workflow engine, which is unauthenticated and unsandboxed, with confirmed exploitation in the last 7 days.
Research & Knowledge
Safe Security