ServiceNow warns of three max severity security vulnerabilities
PatchServiceNow AI PlatformOur summary
ServiceNow has issued security updates for three maximum-severity vulnerabilities affecting its AI Platform, addressing weaknesses that enable code injection, SQL injection, and privilege escalation. These defects (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820) are exploitable by unauthenticated attackers without user interaction, posing significant risks to enterprise environments relying on the platform. While no active exploitation has been confirmed for these specific issues, the company urges immediate patch application for self-hosted instances.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.