ServiceNow has announced the release of patches addressing four significant security vulnerabilities in its AI Platform. Among these, three vulnerabilities have been assigned a maximum severity rating of 10.0 on the CVSS scoring system, indicating a high risk of exploitation by unauthenticated attackers under certain conditions.
Details of the Vulnerabilities
The vulnerabilities are detailed as follows:
- CVE-2026-18885 (CVSS score: 10.0) – A code injection vulnerability in the GraphQL Composite Data API, allowing an unauthenticated user to execute arbitrary code and access or modify instance data.
- CVE-2026-18886 (CVSS score: 10.0) – An improper access control vulnerability in the system configuration image upload processor, enabling an unauthenticated user to create or modify instance data, leading to privilege escalation.
- CVE-2026-74820 (CVSS score: 10.0) – A SQL injection vulnerability via a dynamic schema ORDER BY clause, permitting an unauthenticated user to execute arbitrary SQL statements against the instance’s database.
- CVE-2026-6876 (CVSS score: 8.7) – A sandbox escape that could allow an unauthenticated user to execute arbitrary code within the Now Platform.
Impact and Exploitation Potential
The three maximum-severity vulnerabilities share a CVSS vector indicating a network-reachable attack of low complexity that requires no privileges or user interaction. This could significantly impact the confidentiality, integrity, and availability of both the vulnerable components and connected systems. ServiceNow has indicated that it is not currently aware of any exploitation of these vulnerabilities.
Patch Availability and Recommendations
ServiceNow has deployed a security update to its hosted instances and has provided updates to its partners and self-hosted customers. Organizations running their own instances are advised to apply the necessary patches. The advisory was published on August 27, 2026, and the affected versions include:
- Xanadu – any version before Patch 11 Hot Fix 7a
- Yokohama – any version before Patch 12 Hot Fix 3b and Patch 13 Hot Fix 4
- Zurich – any version before Patch 7b Hot Fix 3, Patch 8 Hot Fix 5, Patch 9 Hot Fix 6, Patch 10 Hot Fix 2m (m-branch), and Patch 10 Hot Fix 3 (standard)
- Australia – any version before Patch 2 Hot Fix 3, Patch 3 Hot Fix 2, Patch 3m, Patch 4, or Patch 5
Context on Vulnerability Ratings
The ratings for these vulnerabilities are determined by ServiceNow, which acts as the CVE Numbering Authority for its products. As of August 28, 2026, none of the vulnerabilities have been listed in CISA’s Known Exploited Vulnerabilities catalog, meaning ServiceNow’s assessments are currently the only severity ratings available.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








