ServiceNow has issued important security patches addressing four vulnerabilities in its Now Platform and ServiceNow AI platform. Three of these vulnerabilities are deemed critical, posing substantial risks such as unauthorized code execution, data access, record modification, and privilege escalation. These updates, released in August 2026, are crucial for maintaining system security.
Overview of the Security Flaws
On August 27, ServiceNow published a CVE advisory detailing how these vulnerabilities were identified through internal security efforts and responsible disclosure practices. The company emphasized the need for self-hosted ServiceNow users to promptly apply updates or upgrade to the latest patched versions to mitigate these risks.
Among the critical vulnerabilities, CVE-2026-18885 is a code injection issue that could allow attackers to execute arbitrary code within the ServiceNow platform. This exploitation risk is significant for organizations relying on ServiceNow for IT management, security workflows, and enterprise automation.
Detailed Analysis of Critical Vulnerabilities
The second critical flaw, identified as CVE-2026-18886, also involves code injection in the ServiceNow AI platform. This vulnerability could enable unauthorized users to alter instance data and escalate privileges, leading to potential unauthorized access.
Another major concern is CVE-2026-74820, a SQL injection vulnerability. This flaw allows attackers to execute arbitrary SQL statements, posing a threat to sensitive data and database integrity. Additionally, ServiceNow addressed a high-severity sandbox escape vulnerability, CVE-2026-6876, in its Now Platform, which poses risks of unauthorized code execution.
Recommended Actions for ServiceNow Users
ServiceNow has already deployed updates to clients enrolled in their Patching Program. Organizations must ensure their systems are running patched versions, including Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b, Patch 13 Hot Fix 4, and other supported updates.
For self-hosted ServiceNow environments, addressing the three critical AI platform vulnerabilities should be a top priority. Security teams need to verify installed versions, apply necessary hotfixes, and monitor system activities for unusual behavior such as unexpected data changes or unauthorized code execution.
In conclusion, the timely application of these security patches is essential for protecting ServiceNow deployments from potential exploitation. By staying updated and vigilant, organizations can safeguard their operational data and maintain the integrity of their IT processes.
