• News/
  • bleepingcomputer-20260828102942

ServiceNow warns of three max severity security vulnerabilities

BleepingComputer
·
Sergiu Gatlan
·
Published Aug 28, 2026
·
Updated

ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. The ServiceNow AI Platform (formerly known as the Now Platform) is an enterprise-grade Platform-as-a-Service (PaaS) that helps integrate AI into core enterprise workflows and powers more than 100,000 enterprise AI apps at 85% of all Fortune 500 companies. In a Thursday advisory, the company said it patched its cloud-based platform against the three critical security flaws (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820) and advised customers to secure their self-hosted instances. The first is a code injection vulnerability that can allow attackers to execute arbitrary code, the second stems from a code injection weakness that enables them to escalate privileges, and the third allows threat actors to access or modify instance data through SQL injection attacks. All three security vulnerabilities can be exploited by unauthenticated threat actors in low-complexity attacks that don't require user interaction. On Thursday, ServiceNow also addressed a high-severity sandbox escape security issue (CVE-2026-6876) affecting the same platform that could let attackers with basic privileges gain remote code execution on targeted systems. "We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched ...

Read full article

Affected Software

4 affected components
ServiceNow AI Platform (formerly known as the Now Platform)=CVE-2026-18885
ServiceNow AI Platform (formerly known as the Now Platform)=CVE-2026-18886
ServiceNow AI Platform (formerly known as the Now Platform)=CVE-2026-74820
ServiceNow AI Platform (formerly known as the Now Platform)=CVE-2026-6876

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203