CVE Tools

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

The Hacker NewsBy The Hacker News

PatchServiceNow AI Platform

Our summary

ServiceNow has deployed security updates to address four vulnerabilities in its AI Platform, including three flaws rated CVSS 10.0 that permit unauthenticated attackers to execute arbitrary code or inject SQL. The advisory covers CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, all of which require low complexity and no prior authorization to compromise instance confidentiality and integrity. A fourth flaw, CVE-2026-6876, allows for sandbox escape. Organizations running self-hosted instances must manually apply the relevant hotfixes, such as Patch 11 Hot Fix 7a for Xanadu, while hosted instances have already received the update.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store