Skip to main content
← Back to blog

ServiceNow AI Platform: Three CVSS 10.0 Flaws Require Immediate Patching

ServiceNow disclosed three unauthenticated, low-complexity vulnerabilities in its AI Platform, each rated CVSS 10.0. Hosted instances were patched by the vendor, but self-hosted customers should urgently deploy the released hotfixes and validate exposure paths for code and SQL injection risks.

#servicenow#cve#cloudsecurity#patchmanagement#sqlinjection#codeinjection
ServiceNow AI Platform: Three CVSS 10.0 Flaws Require Immediate Patching

ServiceNow AI Platform Patches Three Critical Pre-Auth Risks

What happened

ServiceNow released security fixes for multiple AI Platform vulnerabilities, including three issues rated CVSS 10.0. The flaws span code injection, privilege-related abuse paths, and SQL injection conditions that can be triggered without authentication in low-complexity scenarios.

Who is affected

Organizations running self-hosted ServiceNow AI Platform instances are the primary risk group because cloud-hosted instances were patched by ServiceNow.

Why it matters

ServiceNow is deeply integrated into IT, security, and business workflows. Critical pre-auth flaws in this layer can create high-impact risk, including unauthorized data access, integrity impact, and potential downstream process disruption.

Technical details

  • CVE-2026-18885: pre-auth code injection (CVSS 10.0)
  • CVE-2026-18886: pre-auth issue enabling privileged abuse and data impact (CVSS 10.0)
  • CVE-2026-74820: SQL injection affecting instance data access/modification (CVSS 10.0)
  • Additional issue: CVE-2026-6876 (high severity) affecting sandbox boundaries
  • Exploitation status at publication: no confirmed active exploitation reported by vendor
  • Patched release trains include updated hotfix lines across Xanadu, Yokohama, Zurich, and Australia branches

Recommended actions

  • Apply the latest vendor hotfixes immediately on self-hosted instances.
  • Prioritize externally reachable admin/API surfaces.
  • Review access controls and segmentation around ServiceNow application tiers.
  • Audit logs for anomalous unauthenticated requests, query abuse patterns, and unexpected configuration changes.
  • Coordinate with change management and incident response teams to validate platform integrity after patching.

Sources

  • https://www.bleepingcomputer.com/news/security/servicenow-warns-of-three-max-severity-security-vulnerabilities/
  • https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3152242