ServiceNow has released security updates for three critical vulnerabilities in its AI Platform. The flaws could allow unauthenticated attackers to perform code injection, SQL injection, and privilege escalation attacks.
The ServiceNow AI Platform, formerly known as the Now Platform, is an enterprise-grade Platform-as-a-Service (PaaS) designed to integrate artificial intelligence into business workflows. The platform powers more than 100,000 enterprise AI applications and is used by organizations representing 85% of Fortune 500 companies.
In a security advisory issued Thursday, ServiceNow disclosed three maximum-severity vulnerabilities—CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. The company urged customers with self-hosted ServiceNow instances to apply the available security updates as soon as possible.
CVE-2026-18885 is a code injection vulnerability that can enable attackers to execute arbitrary code. CVE-2026-18886 is another code injection flaw that could allow attackers to escalate privileges. CVE-2026-74820 is a SQL injection vulnerability that may provide unauthorized access to, or allow modification of, data stored on a ServiceNow instance.
All three critical vulnerabilities can be exploited remotely by unauthenticated attackers. The attacks are considered low complexity and do not require user interaction.
ServiceNow also fixed a high-severity sandbox escape vulnerability, tracked as CVE-2026-6876. The flaw affects the same platform and could allow an attacker with basic privileges to escape the sandbox and execute remote code on the targeted system.
| Release | Updated version |
| Xanadu | Patch 11 Hotfix 7a |
| Yokohama | Yokohama Patch 12 Hotfix 3b Yokohama Patch 13 Hotfix 4 |
| Zurich | Zurich Patch 7b Hotfix 3 Zurich Patch 8 Hotfix 5 Zurich Patch 9 Hotfix 6 Zurich Patch 10 Hot Fix 2m (m branch) Zurich Patch 10 Hot Fix 3 (Standard) Zurich Patch 11 Zurich Patch 12 |
| Australia | Australia Patch 2 Hotfix 3 Australia Patch 3 Hotfix 2 Australia Patch 3m Australia Patch 4 Australia Patch 5 |
“We are currently not aware of any malicious exploitation targeting ServiceNow instances. We encourage customers to promptly apply the appropriate updates or upgrade to a patched release if they have not already done so,” ServiceNow said.
Although ServiceNow has not reported active exploitation of the vulnerabilities patched Thursday, attackers have targeted multiple ServiceNow security flaws in recent years. Organizations should prioritize updating affected AI Platform and self-hosted deployments to reduce their exposure.
Two years ago, threat actors used publicly available exploits to chain three ServiceNow vulnerabilities—CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217. The attacks enabled data theft from private companies and government agencies worldwide.
More recently, in July, threat intelligence company Defused reported that attackers were exploiting another critical ServiceNow AI Platform vulnerability, CVE-2026-6875, a pre-authentication sandbox escape flaw.
Last month, ServiceNow also privately disclosed a security incident involving an unauthenticated access vulnerability. According to the company, a security researcher or customer-led investigation exploited the flaw to query data from a customer instance through a vulnerable API endpoint.
The overall prevention score can obscure what happens after an attacker gains initial access. When valid credentials are used, the effectiveness of your defenses can decline sharply.
Blue Report 2026 evaluates defense techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




