Cybersecurity

ServiceNow Releases Urgent Updates for Three Maximum-Severity Vulnerabilities in AI Platform

ServiceNow fixed three maximum-severity security vulnerabilities in AI Platform that could be exploited to execute code, inject SQL, and escalate privileges without authentication or user interaction. The company is urging customers with self-hosted instances to update quickly, while confirming that it has not observed malicious exploitation of these vulnerabilities so far.

2026-08-28
3 min read
8 views
فريق تحرير certi.news
ServiceNow Releases Urgent Updates for Three Maximum-Severity Vulnerabilities in AI Platform

On August 28, 2026, ServiceNow released security updates to address three new maximum-severity vulnerabilities in the ServiceNow AI Platform, formerly known as the Now Platform. The platform enables the integration of artificial intelligence capabilities into enterprise workflows and is used by more than 100,000 enterprise AI applications at 85% of Fortune 500 companies, according to the information provided in the report.

The vulnerabilities are CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. The company said it secured its cloud platform against the flaws, while urging customers who manage self-hosted instances to apply the appropriate updates or upgrade to a fixed version.

Three Different Attack Paths

The first vulnerability can be exploited to execute arbitrary code through a code injection attack. The second also results from a code injection weakness, but could allow an attacker to escalate privileges. The third allows access to or modification of instance data through SQL injection attacks.

All three vulnerabilities share characteristics that increase their operational risk: an unauthenticated attacker can exploit them, the attacks are low-complexity, and they require no user interaction. These characteristics reduce the requirements needed to access affected systems, particularly when the platform is connected to sensitive enterprise data and workflows.

On the same day, ServiceNow also addressed a high-severity sandbox escape vulnerability, identified as CVE-2026-6876. This vulnerability could allow an attacker with basic privileges to obtain remote code execution on targeted systems.

Versions Including the Fixes

The updates covered multiple versions of the platform, including:

  • Xanadu: Patch 11 Hot Fix 7a.
  • Yokohama: Patch 12 Hot Fix 3b and Patch 13 Hot Fix 4.
  • Zurich: Patch 7b Hot Fix 3, Patch 8 Hot Fix 5, and Patch 9 Hot Fix 6, in addition to Patch 10, Patch 11, and Patch 12 releases with the specified fix levels for each branch.
  • Australia: Patch 2 Hot Fix 3, Patch 3 Hot Fix 2, Patch 3m, Patch 4, and Patch 5.

Why Does This News Matter?

ServiceNow confirmed that it currently has no indicators of malicious exploitation of the four vulnerabilities addressed in this release. However, the absence of observed exploitation does not eliminate the priority of updating, because the maximum-severity vulnerabilities require neither authentication nor user interaction, and because the platform may be part of broad enterprise operations.

This warning is based on a previous record mentioned in the report: in 2024, attackers sequentially exploited three vulnerabilities in ServiceNow—CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217—using publicly available exploit tools to breach private companies and government agencies around the world and steal data. In July, threat intelligence company Defused reported the exploitation of CVE-2026-6875, another critical pre-authentication sandbox escape vulnerability in AI Platform.

ServiceNow also privately disclosed the previous month a security incident in which security researchers or customer-led research teams used an unauthenticated access flaw through a vulnerable API endpoint to query data from customer instances. The source does not establish that this incident is connected to the three new vulnerabilities, so the relationship between them remains unconfirmed.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news