ServiceNow warns of three maximum severity security vulnerabilities

ServiceNow

ServiceNow has released security fixes for three new maximum severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks.

The ServiceNow AI Platform (formerly the Now Platform) is an enterprise-class Platform as a Service (PaaS) that helps integrate AI into core enterprise workflows and powers more than 100,000 enterprise AI applications across 85% of all Fortune 500 companies.

In an announcement Thursday, the company said it has patched its cloud-based platform against the three critical security vulnerabilities (CVE-2026-18885, CVE-2026-18886and CVE-2026-74820) and advised customers to secure their self-hosted instances.

image

The first is a code injection vulnerability that could allow attackers to execute arbitrary code, the second stems from a code injection weakness that allows them to escalate privileges, and the third allows threat actors to access or modify instance data via SQL injection attacks.

All three security vulnerabilities can be exploited by unauthorized threat actors in low-sophistication attacks that do not require user interaction.

On Thursday, ServiceNow also addressed a high-severity sandbox escape security issue (CVE-2026-6876), affecting the same platform, which could allow root-privileged attackers to obtain remote code execution on target systems.






Liberation Updated version
Xanadu Patch 11 Hot Fix 7a
Yokohama Yokohama Patch 12 Hot Fix 3b
Yokohama Patch 13 Hot Fix 4
Zurich Zurich Patch 7b Hot Fix 3
Zurich Patch 8 Hot Fix 5
Zurich Patch 9 Hot Fix 6
Zurich Patch 10 Hot Fix 2m (m-branch)
Zurich Patch 10 Hot Fix 3 (Standard)
Zurich 11 patch
Zurich 12 patch
Australia Australia Patch 2 Hot Fix 3
Australia Patch 3 Hot Fix 2
Australia Patch 3m
Australia Patch 4
Australia Patch 5

“At this time, we are not aware of any malicious exploitation against ServiceNow instances. We recommend that customers immediately apply appropriate updates or upgrade to a patched version if they have not already done so.” the company said.

Although ServiceNow did not mark any of the vulnerabilities patched on Thursday as being actively exploited, numerous security flaws in ServiceNow products have been the target of attacks in recent years.

Two years ago, threat actors linked three ServiceNow vulnerabilities (CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217) using publicly available exploits to penetrate private businesses and government agencies around the world in data theft attacks.

Most recently, in July, threat intelligence company Defused reported that attackers are now exploiting another critical vulnerability (CVE-2026-6875), pre-authentication sandbox evasion in the ServiceNow AI platform.

ServiceNow also privately disclosed a security incident last month in which security researchers or customer-led research used an unauthenticated access loophole through a vulnerable API endpoint to request data from client instances.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *