ServiceNow fixes 3 critical code injection vulnerabilities

ServiceNow announced fixes for four vulnerabilities, including three critical code injection flaws in the ServiceNow AI platform, each with maximum severity (CVSS score of 10/10).

The first of the critical bugs, tracked as CVE-2026-18885, allows an attacker to execute arbitrary code on the ServiceNow platform under certain circumstances.

An attacker could use the weakness to access and potentially modify arbitrary data, ServiceNow notes in its consultative.

The second critical flaw, CVE-2026-18886, is described as an issue with improper access control. This could allow an attacker to create or modify arbitrary data and elevate their privileges.

Tracked as CVE-2026-74820, the third critical vulnerability is an SQL injection flaw that allows an attacker to execute arbitrary SQL statements against the underlying ServiceNow database.

An attacker could use the flaw to “access or modify instance data beyond what was intended,” ServiceNow says.

Advertising. Scroll to continue reading.

According to the company, none of the three vulnerabilities required authentication or user interaction. All three can be used in low complexity attacks.

The fourth issue, tracked as CVE-2026-6876 (CVSS score of 8.7), is a highly serious sandboxing vulnerability that could be exploited without authentication to execute code within the Now platform.

An attacker could use the security flaw to gain “more access to the Now platform than intended,” the company said.

ServiceNow says it has released patches for all four vulnerabilities in its hosted instances. The company also released hotfixes for self-hosted copies, encouraging customers to apply them as soon as possible.

Hotfixes are available for the Xanadu, Yokohama, Zurich, and Australia editions of ServiceNow.

According to iCOUNTER Director of Anti-Fraud Operations Jason Brown, security teams should prioritize patching their ServiceNow instances as attackers quickly take advantage of newly discovered vulnerabilities.

“Anyone running ServiceNow on their own infrastructure now has to find, schedule and apply this patch themselves, and in many organizations the process takes weeks, not days. During those weeks, an unauthenticated hacker with a working exploit for a GraphQL Composite Data API code injection bug or SQL injection flaw has a real shot at systems that sit next to HR records, vendor onboarding and financial approvals,” Brown said.

“I’ve spent years chasing fraud operators who specifically target this delay between detection and patch adoption because they know that’s where the easy access is. My advice to any security team running self-hosted ServiceNow right now is simple: don’t wait for your normal patch cycle, treat this one as urgent and confirm it’s applied this week,” he added.

Related: Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

Related: CISA warns of exploited Gitea vulnerability

Related: Hidden ‘City-Forum’ attacks target Salesforce and ServiceNow with custom toolset

Related: Exploitation of ServiceNow vulnerability observed days after disclosure

Leave a Reply

Your email address will not be published. Required fields are marked *