ServiceNow has released security patches for four vulnerabilities affecting its AI Platform, including three flaws assigned the maximum CVSS score of 10.0 that could, under certain conditions, allow unauthenticated attackers to execute arbitrary code, manipulate instance data, or perform SQL injection attacks. The company stated that security updates have already been deployed to ServiceNow hosted instances, while patches have also been made available to partners and customers operating self hosted deployments. Organizations managing their own ServiceNow environments have been advised to apply the updates to protect their systems. The security advisory was published on August 27, 2026, and ServiceNow noted that it is not currently aware of any active exploitation involving the newly disclosed vulnerabilities.
The three critical vulnerabilities include CVE 2026 18885, a code injection flaw in the GraphQL Composite Data API that could enable an unauthenticated attacker to execute arbitrary code and gain access to or modify instance data. CVE 2026 18886 is an improper access control issue affecting the system configuration image upload processor, potentially allowing attackers to create or modify instance data and elevate privileges. The third maximum severity issue, CVE 2026 74820, is a SQL injection vulnerability in a dynamic schema ORDER BY clause that could enable arbitrary SQL execution against the underlying database without authentication. ServiceNow also addressed CVE 2026 6876, a sandbox escape vulnerability assigned a CVSS score of 8.7 that could allow arbitrary code execution within the Now Platform. According to the company, the three CVSS 10.0 vulnerabilities are network reachable, require no user interaction or privileges, and have a significant potential impact on confidentiality, integrity, and availability. The lower rated sandbox escape differs by requiring low level privileges and affecting only the vulnerable component rather than connected systems.
The latest advisory follows the disclosure of CVE 2026 6875, a pre authentication sandbox escape vulnerability previously reported to ServiceNow by Searchlight Cyber on April 1, 2026, with a public advisory released in July. Shortly after that disclosure, threat intelligence firm Defused reported observing activity that appeared to exploit the flaw in real world environments before later clarifying that the captured payload matched Searchlight Cyber’s publicly available proof of concept rather than confirmed malicious exploitation. In response, ServiceNow stated that its investigation had not identified evidence that the reported activity affected ServiceNow hosted environments. The company encouraged both hosted and self hosted customers to install available patches and confirmed that it would continue assisting customers requiring support with the update process. ServiceNow also explained that the CVSS ratings for the new vulnerabilities were assigned internally because the company serves as the CVE Numbering Authority for its own products. As of August 28, 2026, none of the newly disclosed flaws had been added to CISA Known Exploited Vulnerabilities catalog, making ServiceNow’s assessment the only published severity rating.
ServiceNow listed multiple affected product releases across the Xanadu, Yokohama, Zurich, and Australia versions of the platform, with numerous patches and hot fixes available to resolve the issues. The advisory noted a minor inconsistency in the product status recorded for CVE 2026 18886 compared with the remaining vulnerabilities, although all four records indicate that releases not specifically identified fall outside the affected versions. The company also confirmed that no public exploit code for the three newly disclosed CVSS 10.0 vulnerabilities had been identified as of August 28, 2026. Researchers also noted that Searchlight Cyber had not yet published a technical analysis of the newly disclosed flaws. The disclosures highlight the importance of timely patch management for organizations operating ServiceNow environments, particularly those using self hosted deployments, where administrators are responsible for applying updates to address critical security vulnerabilities before they can be leveraged in future attacks.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





