Three maximum-severity flaws in ServiceNow AI
Code injection, privilege escalation and SQL injection, all reachable without authentication and without user interaction.
2 minEnterprise CyberSec
ServiceNow has patched three maximum-severity vulnerabilities in its AI Platform, the product formerly sold as the Now Platform, and told customers running self-hosted instances to secure them. The cloud-based platform was patched by the company.
The three are tracked as CVE-2026-18885, CVE-2026-18886 and CVE-2026-74820. The first allows arbitrary code execution through code injection. The second is a code injection weakness that leads to privilege escalation. The third permits reading or modifying instance data through SQL injection.
What makes the set unusually serious is not the categories but the preconditions, or rather their absence. All three can be exploited by unauthenticated attackers, in low-complexity attacks, with no user interaction required. There is no phishing step and no insider to compromise first.
A fourth issue disclosed the same day, CVE-2026-6876, is a high-severity sandbox escape in the same platform that could give an attacker holding basic privileges remote code execution.
The exposure is a function of where the product sits. ServiceNow describes the platform as powering more than 100,000 enterprise AI applications at 85% of the Fortune 500 — which is to say the workflow layer that connects other systems, and therefore holds credentials for them.
The company said it is not currently aware of malicious exploitation and recommended customers apply the updates or upgrade to a patched release. That is worth reading precisely: no evidence of exploitation is not evidence of no exploitation, and ServiceNow flaws have been chained in attacks before, using publicly available exploits.
Retold from BleepingComputer. This is a summary in our own words; follow the link for the original reporting.