ServiceNow has released patches to address vulnerabilities in its AI platform, including three critical code injection flaws. These vulnerabilities, identified as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, have been assigned the highest severity rating with a CVSS score of 10/10.
Details of Critical Vulnerabilities
The first vulnerability, CVE-2026-18885, enables attackers to execute arbitrary code on the ServiceNow platform under specific conditions. Exploiting this flaw could allow unauthorized access to alter data, as noted in ServiceNow’s advisory.
CVE-2026-18886 is another critical vulnerability, characterized by improper access control. This flaw may permit an attacker to modify data and escalate their privileges within the system.
The third critical issue, CVE-2026-74820, is an SQL injection vulnerability. This allows an attacker to run arbitrary SQL commands on the ServiceNow database, potentially accessing or modifying data beyond intended permissions.
Exploitation and Impact
ServiceNow has clarified that these vulnerabilities do not require authentication or user interaction, making them susceptible to low-complexity attacks. The fourth issue, CVE-2026-6876, is a high-severity sandbox escape vulnerability, with a CVSS score of 8.7, which can also be exploited without authentication.
This sandbox escape flaw could provide more access than intended within the Now Platform. ServiceNow has implemented patches across its hosted instances and released hotfixes for self-hosted instances, urging users to apply them promptly.
Security Recommendations
Jason Brown, director of counter fraud operations at iCOUNTER, emphasizes the urgency of patching these vulnerabilities. He warns that attackers exploit the delay between vulnerability disclosure and patch application, targeting gaps in security.
Brown advises organizations running self-hosted ServiceNow instances to bypass normal patching cycles and apply these updates immediately. The urgency stems from the potential exposure of critical systems, including HR records and financial approvals, to unauthorized access.
Proactive patch management is crucial in mitigating risks associated with these vulnerabilities. Organizations are encouraged to confirm the application of patches to safeguard against exploitation.
Related articles highlight similar cybersecurity challenges, such as critical vulnerabilities in Ruby on Rails, Gitea, and targeted attacks on platforms like Salesforce and ServiceNow.
