ServiceNow Patches 3 Critical Code Injection Vulnerabilities
PatchServiceNow Now PlatformOur summary
ServiceNow has issued updates addressing four security defects, including three critical vulnerabilities rated CVSS 10.0 within its AI platform. These high-severity issues—identified as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820—permit unauthenticated remote code execution and privilege escalation without requiring user interaction. Additionally, a high-severity sandbox escape flaw (CVE-2026-6876) was addressed in the same release. The vendor has distributed hotfixes for self-hosted instances across its Xanadu, Yokohama, Zurich, and Australia releases.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.