CVE Tools

ServiceNow warns of three max severity security vulnerabilities

BleepingComputerBy Sergiu Gatlan

PatchServiceNow AI Platform

Our summary

ServiceNow has issued security updates for three maximum-severity vulnerabilities affecting its AI Platform, addressing weaknesses that enable code injection, SQL injection, and privilege escalation. These defects (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820) are exploitable by unauthenticated attackers without user interaction, posing significant risks to enterprise environments relying on the platform. While no active exploitation has been confirmed for these specific issues, the company urges immediate patch application for self-hosted instances.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store