ServiceNow Patches Three Maximum-Severity Flaws That Allowed Unauthenticated Code Execution

ServiceNow disclosed and patched three maximum-severity vulnerabilities in its Now Platform and AI Platform on August 28, 2026, each exploitable by an unauthenticated attacker with low complexity and no user interaction, according to the company’s own security advisories and reporting from BleepingComputer and The Hacker News.

Two of the flaws, CVE-2026-18885 and CVE-2026-18886, are code-injection vulnerabilities in the ServiceNow AI Platform that could let an attacker execute arbitrary code, access or modify instance data beyond intended permissions, or escalate privileges. A third, CVE-2026-74820, is a SQL-injection flaw in the same platform that could allow an unauthenticated user to run arbitrary SQL statements against the underlying database and alter instance data. A separate, high-severity sandbox-escape bug, CVE-2026-6876, was disclosed alongside the three critical issues.

No Confirmed Exploitation, but a Pattern of Prior Abuse

ServiceNow said it is “not currently aware of malicious exploitation against ServiceNow instances” tied to the newly disclosed flaws. The company has hosted-instance customers already patched, while partners and self-hosted customers running on-premises deployments are responsible for applying fixes themselves across the affected Xanadu, Yokohama, Zurich, and Aspen release families.

The disclosure follows a related ServiceNow flaw, CVE-2026-6875, that researchers confirmed was actively exploited in July 2026, and echoes a pattern from 2024 in which several ServiceNow vulnerabilities were chained together in attacks against government and private-sector targets. Given ServiceNow’s widespread use for enterprise workflow and identity-adjacent processes, security teams are advised to prioritize patching self-hosted instances even in the absence of confirmed in-the-wild exploitation.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *