ServiceNow warns of three max severity security vulnerabilities

ServiceNow has issued a critical warning about three maximum-severity security vulnerabilities affecting its AI Platform, which provides enterprise-grade Platform-as-a-Service (PaaS) to over 100,000 apps at 85% of all Fortune 500 companies. The company has released patches for the vulnerabilities, which can be exploited by unauthenticated attackers in low-complexity attacks that don’t require user interaction.

The three maximum-severity vulnerabilities, identified as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, affect the ServiceNow AI Platform’s ability to prevent code injection, SQL injection, and privilege escalation attacks. These types of attacks can allow hackers to execute arbitrary code, access or modify instance data, and escalate privileges on targeted systems.

What’s particularly concerning is that all three vulnerabilities can be exploited by attackers who don’t need valid credentials to launch an attack. This means that any unauthenticated user with basic knowledge of how these vulnerabilities work can potentially compromise a ServiceNow AI Platform instance. While ServiceNow claims it has no evidence of malicious exploitation against its instances, the company is urging customers to apply patches or upgrade to a patched release as soon as possible.

The ServiceNow AI Platform is widely used by large enterprises and government agencies worldwide, which makes these vulnerabilities particularly concerning from a security perspective. In recent years, multiple security flaws in ServiceNow products have been targeted in attacks, including a 2024 incident where threat actors chained three ServiceNow flaws to breach private firms and government agencies globally.

What’s also worth noting is that once attackers gain valid credentials on a ServiceNow instance, the prevention capabilities of the platform drop sharply. According to research from Defused, only 37% of an attacker’s actions are blocked when they use valid credentials. This highlights the importance of timely patching and vulnerability management in preventing attacks.

In light of this warning, it’s essential for all ServiceNow customers to review their instance configurations and ensure that the latest patches have been applied. This is a critical reminder that even with robust security measures in place, vulnerabilities can still be exploited if not addressed promptly. As a best practice, organizations should regularly monitor their systems for updates and apply patches as soon as possible to prevent potential attacks.

Readers are advised to review the ServiceNow advisory and follow the recommended update schedule to ensure their instances remain secure. It’s also crucial to maintain up-to-date knowledge of vulnerabilities and corresponding patches to stay ahead of potential threats in the ever-evolving cybersecurity landscape.


Source: Bleeping Computer — 2026-08-28