started · updated
ServiceNow patches critical vulnerabilities in AI Platform
ServiceNow has released security patches for several vulnerabilities in its AI Platform, including three flaws categorized with maximum severity. These vulnerabilities, discovered through internal security research, could allow unauthenticated attackers to execute arbitrary code, access or modify sensitive instance data, and escalate privileges.
The critical flaws are tracked as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. Specifically, CVE-2026-18885 involves code injection that could lead to unauthorized data access, while CVE-2026-18886 could allow attackers to alter data and escalate privileges. The SQL injection vulnerability, CVE-2026-74820, permits the execution of arbitrary SQL statements against an instance’s underlying database.
Additionally, a high-severity sandbox escape vulnerability, CVE-2026-6876, was patched. While ServiceNow’s cloud-based instances have already been updated, the company advises self-hosted customers to apply patches or upgrade immediately. ServiceNow stated it is not currently aware of any active exploitation of these flaws.