Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
PatchServiceNow AI PlatformOur summary
ServiceNow has deployed security updates to address four vulnerabilities in its AI Platform, including three flaws rated CVSS 10.0 that permit unauthenticated attackers to execute arbitrary code or inject SQL. The advisory covers CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, all of which require low complexity and no prior authorization to compromise instance confidentiality and integrity. A fourth flaw, CVE-2026-6876, allows for sandbox escape. Organizations running self-hosted instances must manually apply the relevant hotfixes, such as Patch 11 Hot Fix 7a for Xanadu, while hosted instances have already received the update.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.