VMTech
Discuss a project

ServiceNow Patches Three Maximum-Severity AI Platform Flaws

ServiceNow Patches Three Maximum-Severity AI Platform Flaws

ServiceNow has released fixes for four security vulnerabilities in its ServiceNow AI Platform, including three that it rated CVSS 10.0. In certain circumstances, the three maximum-severity flaws could be exploited by an unauthenticated attacker to execute arbitrary code or SQL, access or modify instance data, or escalate privileges.

The company said it deployed the security update to hosted instances and supplied it to partners and self-hosted customers. Organisations operating their own ServiceNow instances must apply the relevant fixes themselves. ServiceNow published its advisory on August 27, 2026.

Three flaws receive a CVSS 10.0 rating

CVE-2026-18885 is a code-injection issue in the GraphQL Composite Data API. ServiceNow said an unauthenticated user could execute arbitrary code and gain access to, or modify, instance data.

CVE-2026-18886 affects the system configuration image-upload processor. The improper access-control flaw could allow an unauthenticated user to create or modify instance data, resulting in privilege escalation. CVE-2026-74820 is a SQL-injection vulnerability reachable through a dynamic-schema ORDER BY clause and could enable arbitrary SQL statements against the underlying database.

ServiceNow assigned the same CVSS 4.0 vector to the three CVSS 10.0 issues: network access, low attack complexity, no required privileges and no user interaction. The vector records high effects on confidentiality, integrity and availability for both the vulnerable component and connected systems.

A fourth issue and affected release families

The fourth flaw, CVE-2026-6876, is a sandbox escape in the Now Platform rated 8.7. ServiceNow describes it as potentially allowing arbitrary code execution by an unauthenticated user, although the CVSS vector assigned to it records low privileges required and no impact beyond the vulnerable component.

The advisory lists affected releases in the Xanadu, Yokohama, Zurich and Australia families. Required fixes include Xanadu Patch 11 Hot Fix 7a; Yokohama Patch 12 Hot Fix 3b or Patch 13 Hot Fix 4; and several listed patch and hot-fix levels for Zurich and Australia. The CVE-2026-18886 record marks versions before Australia Patch 5 as unknown, while the other three records mark that same range as affected.

ServiceNow said it is not currently aware of exploitation of any of the four newly disclosed flaws. The Hacker News found no public exploit code for the three CVSS 10.0 issues as of August 28, and Searchlight Cyber had not published a technical write-up for them at that point.

Patch status requires direct verification

The disclosure follows CVE-2026-6875, a pre-authentication sandbox escape for which an advisory was issued in July. Defused initially reported observing exploitation activity, then corrected its statement to say that the captured payload matched Searchlight Cyber's published proof-of-concept. ServiceNow said it had not observed evidence connecting that activity to instances it hosts.

ServiceNow is the CVE Numbering Authority for its products, and the CVSS 10.0 scores are the company's own assessments. None of the four vulnerabilities appeared in CISA's Known Exploited Vulnerabilities catalog as of August 28, 2026. Businesses should inventory self-hosted instances, verify their exact release and patch level against the advisory, and apply the listed updates where their deployment is affected.

#servicenow#cybersecurity#vulnerability#patchmanagement
Open analytics
On the site 1 views
min read 4 28.08.2026
Instagram

ServiceNow Patches Three Maximum-Severity AI Platform Flaws

Open the post on Instagram ↗