ServiceNow Patches Critical Code Injection Vulnerabilities in AI Platform
In a major security patch release, ServiceNow has addressed four vulnerabilities, including three critical code injection flaws in its AI platform. The company’s emergency updates are aimed at preventing attackers from exploiting these weaknesses and gaining unauthorized access to sensitive data.
The three critical bugs, tracked as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, could allow an attacker to execute arbitrary code in the ServiceNow platform. This means that even without authentication or user interaction, a malicious actor can potentially gain access to and modify arbitrary data, including sensitive information stored on the platform.
The first of these critical vulnerabilities is an improper input validation issue (CVE-2026-18885), which could allow attackers to inject malicious code into the ServiceNow system. The second bug (CVE-2026-18886) is described as an access control issue, enabling attackers to create or modify arbitrary data and elevate their privileges. Meanwhile, the third vulnerability (CVE-2026-74820) is a SQL injection flaw that could allow attackers to execute arbitrary SQL statements against the underlying ServiceNow database.
ServiceNow emphasizes that none of these three critical vulnerabilities require authentication or user interaction, making them particularly concerning. What’s more, all three can be exploited in low-complexity attacks, meaning even novice attackers may be able to take advantage of these weaknesses.
The fourth vulnerability (CVE-2026-6876) is a sandbox escape weakness with a CVSS score of 8.7, allowing an attacker to gain more access to the Now Platform than intended without authentication. While this issue is not as severe as the three critical bugs, it still poses a significant threat if left unpatched.
ServiceNow has rolled out patches for all four vulnerabilities across its hosted instances and released hotfixes for self-hosted installations. The company encourages customers to apply these updates as soon as possible, particularly those running ServiceNow’s Xanadu, Yokohama, Zurich, or Australia releases.
Security experts warn that attackers are quick to exploit newly discovered vulnerabilities, making it essential for organizations to prioritize patching their ServiceNow instances promptly. “Everyone running ServiceNow on their own infrastructure now has to go find, schedule, and apply that patch themselves,” says Jason Brown, director of counter fraud operations at iCOUNTER. “During those weeks [between disclosure and patch adoption], an unauthenticated attacker with a working exploit for the GraphQL Composite Data API code injection bug or the SQL injection flaw has a real shot at systems that sit next to HR records, vendor onboarding, and finance approvals.”
Brown emphasizes that security teams should treat this vulnerability as urgent and apply the patches immediately. “My advice is simple: don’t wait for your normal patch cycle, confirm it’s applied this week,” he advises.
In light of these critical vulnerabilities, organizations using ServiceNow should take immediate action to protect their data. By prioritizing patching and applying the latest updates, they can prevent potential attacks and safeguard sensitive information stored on the platform.
Source: SecurityWeek — 2026-08-31