BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ServiceNow Patches Four Flaws, Three Critical CVSS 10.0

ServiceNow patches four AI Platform flaws, three critical CVSS 10.0 allowing unauthenticated remote code execution

  • ServiceNow released patches for four security flaws in its AI Platform, three rated a maximum CVSS 10.0 that allow unauthenticated remote code execution.
  • The flaws include code injection, improper access control, SQL injection, and a sandbox escape, with the three critical ones exploitable without privileges or user interaction.
  • An earlier flaw (CVE-2026-6875) patched in July is already being exploited in the wild, though ServiceNow says it has not seen evidence on its hosted instances.

ServiceNow has patched four vulnerabilities in its AI Platform, three of which carry the highest possible CVSS score of 10.0 and can be exploited by an unauthenticated attacker under certain conditions. The company deployed security updates to hosted instances on August 27, 2026, and advised self-hosted customers to apply the fixes themselves.

- Advertisement -

The three maximum-severity flaws—tracked as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820—all share a CVSS vector describing a network-reachable attack of low complexity that requires no privileges and no user interaction. The vulnerabilities comprise a code injection in the GraphQL Composite Data API, an improper access control in the image upload processor, and a SQL injection via a dynamic ORDER BY clause.

The fourth flaw, CVE-2026-6876 (CVSS 8.7), is a sandbox escape in the Now Platform that could also allow unauthenticated code execution, though its vector requires low privileges. These disclosures follow a previous sandbox escape, CVE-2026-6875, which ServiceNow patched in July after published proof-of-concept exploit code emerged.

Threat intelligence firm Defused reported in-the-wild exploitation of that earlier flaw shortly after the July advisory. A ServiceNow spokesperson told The Hacker News: “Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts.” The company encouraged all customers to apply relevant patches.

ServiceNow assigned its own CVSS ratings because it is the CVE Numbering Authority for its products, and NIST now only enriches vulnerabilities meeting specific federal criteria. None of the four new flaws appear in CISA’s Known Exploited Vulnerabilities catalog as of August 28, 2026.

- Advertisement -

Affected versions include Xanadu, Yokohama, Zurich, and Australia release lines, with specific patch levels detailed in ServiceNow’s advisory. The company stated it is not currently aware of exploitation for the August flaws, and no public exploit code has been found yet.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

EU AI chief says bloc’s rules can handle rogue AI agents

EU tech chief Henna Virkkunen asserts that the bloc’s AI Act is capable of...

Ark Sells AMD, Alphabet, SpaceX; Adds Biotech

Cathie Wood's Ark Invest trimmed stakes in five major tech names across its flagship...

GhostAction compromises two top GitHub devs, hits 340 repos

Two high-profile open-source maintainer accounts were compromised, pushing a malicious workflow into over 340...

OCC fines AmEx $350M over $13B money laundering

The OCC found American Express National Bank processed approximately $13 billion in suspected trade-based...

AnyDesk Linux pre-auth RCE exploit gives root access

Security researchers published AnyPwn, a working exploit for a pre-authentication remote code execution flaw...

Must Read

17 Best Cryptocurrency Wallets

If you are looking for a list with the best cryptocurrency wallets, then you've landed on the right page. Cryptocurrency, as we all know,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading