BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ServiceNow Patches Four Flaws, Three Critical CVSS 10.0

ServiceNow patches four AI Platform flaws, three critical CVSS 10.0 allowing unauthenticated remote code execution

  • ServiceNow released patches for four security flaws in its AI Platform, three rated a maximum CVSS 10.0 that allow unauthenticated remote code execution.
  • The flaws include code injection, improper access control, SQL injection, and a sandbox escape, with the three critical ones exploitable without privileges or user interaction.
  • An earlier flaw (CVE-2026-6875) patched in July is already being exploited in the wild, though ServiceNow says it has not seen evidence on its hosted instances.

ServiceNow has patched four vulnerabilities in its AI Platform, three of which carry the highest possible CVSS score of 10.0 and can be exploited by an unauthenticated attacker under certain conditions. The company deployed security updates to hosted instances on August 27, 2026, and advised self-hosted customers to apply the fixes themselves.

- Advertisement -

The three maximum-severity flaws—tracked as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820—all share a CVSS vector describing a network-reachable attack of low complexity that requires no privileges and no user interaction. The vulnerabilities comprise a code injection in the GraphQL Composite Data API, an improper access control in the image upload processor, and a SQL injection via a dynamic ORDER BY clause.

The fourth flaw, CVE-2026-6876 (CVSS 8.7), is a sandbox escape in the Now Platform that could also allow unauthenticated code execution, though its vector requires low privileges. These disclosures follow a previous sandbox escape, CVE-2026-6875, which ServiceNow patched in July after published proof-of-concept exploit code emerged.

Threat intelligence firm Defused reported in-the-wild exploitation of that earlier flaw shortly after the July advisory. A ServiceNow spokesperson told The Hacker News: “Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts.” The company encouraged all customers to apply relevant patches.

ServiceNow assigned its own CVSS ratings because it is the CVE Numbering Authority for its products, and NIST now only enriches vulnerabilities meeting specific federal criteria. None of the four new flaws appear in CISA’s Known Exploited Vulnerabilities catalog as of August 28, 2026.

- Advertisement -

Affected versions include Xanadu, Yokohama, Zurich, and Australia release lines, with specific patch levels detailed in ServiceNow’s advisory. The company stated it is not currently aware of exploitation for the August flaws, and no public exploit code has been found yet.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Leopold Aschenbrenner Suspected Behind $96M AI Stock Options Bet

AI hedge fund manager Leopold Aschenbrenner is suspected of purchasing $96 million in...

Binance Launches 24/7 FX Perpetuals with USDBRL

Binance launches USDBRL perpetual futures contract on Sept. 21, offering 24/7 trading and up...

WordPress Urges Update as Click2Shell Let Admins Install Themes

WordPress patched the “Click2Shell” vulnerability in version 7.1.1, released September 17, 2026.The flaw lets...

XRP Jumps 7% as Golden Cross Looms Mid-October

XRP surged 6.93% on Friday, climbing from $1.2964 to $1.4028 before settling near $1.3863...

Bitcoin Reclaims $80K as Crypto Stocks Rally on CFTC News

Bitcoin reclaimed $80,000 on Friday for the first time in over a week, sparking...

Must Read

18 Countries With No Privacy Laws According To UN (List)

Privacy laws are legal frameworks designed to protect personal data from unauthorized access, misuse, or disclosure.Lack of privacy laws can lead to misuse of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading