CVE Tools

ServiceNow Patches 3 Critical Code Injection Vulnerabilities

SecurityWeekBy Ionut Arghire

PatchServiceNow Now Platform

Our summary

ServiceNow has issued updates addressing four security defects, including three critical vulnerabilities rated CVSS 10.0 within its AI platform. These high-severity issues—identified as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820—permit unauthenticated remote code execution and privilege escalation without requiring user interaction. Additionally, a high-severity sandbox escape flaw (CVE-2026-6876) was addressed in the same release. The vendor has distributed hotfixes for self-hosted instances across its Xanadu, Yokohama, Zurich, and Australia releases.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store