# ServiceNow cybersecurity and AI platform security

> Live situation record from CLSTR: https://clstr.news/situations/servicenow-cybersecurity-and-ai-platform-security
> Updated: 2026-09-04T14:00:44.000Z. Sources: 4. Developments: 3.

ServiceNow has taken steps to bolster its security infrastructure following reports of cloud exposure. The company launched six integrated solutions, including an AI Control Tower, to provide AI-native cyber defense and manage risks such as exposure, vulnerability detection, and identity security.

Following these developments, ServiceNow released security patches for several vulnerabilities within its AI Platform. This includes three flaws of maximum severity—CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820—which could allow unauthenticated attackers to execute arbitrary code, modify sensitive data, or perform SQL injection. These vulnerabilities, each receiving a maximum CVSS severity score of 10.0, could potentially lead to a full takeover of a ServiceNow instance. The risks are noted to be amplified by the integration of AI agent workflows, which expand the potential attack surface.

The company also patched a high-severity sandbox escape vulnerability, CVE-2026-6876. While cloud-based instances have been updated, the company released hotfixes for self-hosted installations, including the Xanadu, Yokohama, Zurich, and Australia releases. Security experts recommend that organizations prioritize these updates immediately to prevent exploitation, though the company noted it was not aware of any active exploitation of these specific flaws.

In a parallel effort to strengthen cloud security, ServiceNow has partnered with Wiz. This collaboration aims to integrate high-fidelity cloud security data into existing ServiceNow workflows, assisting IT and security teams with tasks such as maintaining accurate inventories of ephemeral workloads, triaging security issues within ITSM, and prioritizing vulnerabilities and misconfigurations based on organizational compliance frameworks.

## Claims

- Horizon3 discovered CVE-2026-9586 in Sangoma Switchvox SMB Edition 8.3. (corroborated by 2 sources)
- Exploitation of CVE-2026-9586 against Switchvox honeypots was observed on August 30, 2026. (corroborated by 2 sources)
- CVE-2026-9586 allows unauthenticated SQL injection and remote code execution via the /paHTTP endpoint. (corroborated by 2 sources)
- The attacker used the IP address 176.65.148.184 to target Switchvox instances. (single source)

## Timeline

### 2026-09-04: ServiceNow patches critical vulnerabilities and partners with Wiz

ServiceNow patched three critical CVSS-10 vulnerabilities while announcing a partnership with Wiz to integrate cloud security data into its existing workflows.

2 sources. https://clstr.news/cluster/servicenow-patches-critical-vulnerabilities-and-partners-with-wiz

### 2026-08-28: ServiceNow patches critical vulnerabilities in AI Platform

ServiceNow has patched three maximum-severity vulnerabilities in its AI Platform that could allow unauthenticated attackers to execute code, modify data, and escalate privileges.

2 sources. https://clstr.news/cluster/servicenow-patches-critical-vulnerabilities-in-ai-platform

### 2026-08-16: ServiceNow launches AI security tools amid cloud exposure reports

ServiceNow launches six AI-driven security solutions to automate cyber defense, amid reports of a 17-month data exposure affecting its and Salesforce's portals via the ‘City-Forum’ campaign.

4 sources. https://clstr.news/cluster/servicenow-launches-ai-security-tools-amid-cloud-exposure-reports

---
Cite as: ServiceNow cybersecurity and AI platform security. CLSTR, https://clstr.news/situations/servicenow-cybersecurity-and-ai-platform-security
