ServiceNow Patches 3 Critical Code Injection Vulnerabilities

ServiceNow’s Critical Code Injection Flaws Exposed: What You Need to Know

A critical security flaw has been uncovered in ServiceNow’s AI platform, leaving thousands of organizations vulnerable to code injection attacks. In a recent announcement, ServiceNow disclosed patches for four vulnerabilities, including three with maximum severity ratings of 10/10 on the Common Vulnerability Scoring System (CVSS). The flaws, which can be exploited without authentication or user interaction, pose a significant threat to data security and integrity.

The first critical vulnerability, tracked as CVE-2026-18885, allows an attacker to execute arbitrary code in the ServiceNow platform under certain circumstances. This could enable an attacker to gain access to and modify arbitrary data, putting sensitive information at risk. The second critical defect, CVE-2026-18886, is an improper access control issue that could allow an attacker to create or modify arbitrary data and elevate their privileges.

The third critical vulnerability, CVE-2026-74820, is an SQL injection flaw that enables an attacker to execute arbitrary SQL statements against the underlying ServiceNow database. This could grant an attacker access to sensitive instance data beyond what was intended. All three vulnerabilities can be exploited in low-complexity attacks, making them a significant concern for organizations running ServiceNow on their own infrastructure.

ServiceNow has rolled out patches for all four vulnerabilities across its hosted instances and released hotfixes for self-hosted instances. Customers are advised to apply these patches as soon as possible to prevent potential exploitation. Jason Brown, director of counter fraud operations at iCOUNTER, emphasizes the importance of prioritizing patching: “Attackers are quick to exploit newly discovered vulnerabilities, so it’s crucial that security teams address this issue promptly.”

The discovery of these critical flaws serves as a reminder of the ongoing threat landscape and the need for organizations to stay vigilant. ServiceNow customers must take immediate action to protect their systems from potential exploitation. As Brown notes, “During those weeks [between disclosure and patch adoption], an unauthenticated attacker has a real shot at systems that sit next to HR records, vendor onboarding, and finance approvals.”

To mitigate this risk, organizations should treat these patches as urgent and confirm their application within the week. This proactive approach will help prevent potential attacks and ensure the security of sensitive data. As the cybersecurity landscape continues to evolve, it’s essential for organizations to stay informed and adapt quickly to emerging threats.


Source: SecurityWeek — 2026-08-31