Ethical Hacking News
ServiceNow has recently announced the release of patches for four security flaws impacting the ServiceNow AI Platform, with three of them rated 10.0 on the Common Vulnerability Scoring System (CVSS) scoring system and potentially exploitable by unauthenticated attackers in certain circumstances. This recent vulnerability highlights the ongoing importance of regular patching and updates for software applications. To protect against these vulnerabilities, organizations should review the affected versions and apply the necessary patches to their instances.
ServiceNow has announced patches for four security flaws in its AI Platform, with three rated 10.0 on the CVSS scoring system. The vulnerabilities are: CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, and CVE-2026-6876. The flaws are potentially exploitable by unauthenticated attackers in certain circumstances. The affected versions are: Xanadu, Yokohama, Zurich, and Australia. The company is not currently aware of exploitation of any of the four vulnerabilities. No public exploit code has been found for the three maximum-severity flaws as of August 28, 2026.
ServiceNow has recently announced the release of patches for four security flaws impacting the ServiceNow AI Platform, with three of them rated 10.0 on the Common Vulnerability Scoring System (CVSS) scoring system and potentially exploitable by unauthenticated attackers in certain circumstances. This recent vulnerability is another concerning security issue that highlights the ongoing importance of regular patching and updates for software applications.
The four vulnerabilities, designated as CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, and CVE-2026-6876, were published on August 27, 2026, and the company has made efforts to provide the update to its partners and self-hosted customers. However, organizations that run their own instances will need to apply the fixes themselves.
CVE-2026-18885, rated 10.0, is a code injection vulnerability in the GraphQL Composite Data API that enables an unauthenticated user to execute arbitrary code and gain access to, or modify, instance data. This vulnerability has a high CVSS score of 10.0 and is considered to be a network-reachable attack with low complexity that requires no privileges and no user interaction.
CVE-2026-18886, also rated 10.0, is an improper access control vulnerability in the system configuration image upload processor that enables an unauthenticated user to create or modify instance data, resulting in privilege escalation. This vulnerability also has a high CVSS score of 10.0 and is considered to be a network-reachable attack with low complexity that requires no privileges and no user interaction.
CVE-2026-74820, rated 10.0, is a SQL injection vulnerability that can be reached through a dynamic schema ORDER BY clause, enabling an unauthenticated user to execute arbitrary SQL statements against the instance's underlying database. This vulnerability also has a high CVSS score of 10.0 and is considered to be a network-reachable attack with low complexity that requires no privileges and no user interaction.
CVE-2026-6876, rated 8.7, is a sandbox escape in the Now Platform that enables an unauthenticated user to execute arbitrary code. This vulnerability has a lower CVSS score of 8.7 but is still considered to be a significant security issue.
The three maximum-severity flaws, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, share the same CVSS vector, which describes a network-reachable attack of low complexity that requires no privileges and no user interaction, and carries high impact to confidentiality, integrity, and availability in both the vulnerable component and the systems connected to it.
ServiceNow has listed the following versions as affected in its August advisory:
* Xanadu - any version before Patch 11 Hot Fix 7a
* Yokohama - any version before Patch 12 Hot Fix 3b, and any version before Patch 13 Hot Fix 4
* Zurich - any version before Patch 7b Hot Fix 3, Patch 8 Hot Fix 5, Patch 9 Hot Fix 6, Patch 10 Hot Fix 2m (m-branch), Patch 10 Hot Fix 3 (standard), Patch 11, or Patch 12
* Australia - any version before Patch 2 Hot Fix 3, Patch 3 Hot Fix 2, Patch 3m, Patch 4, or Patch 5
All four set a default product status of unaffected, which means that a release that falls outside of the affected set is not included in the list.
The record for CVE-2026-18886 marks "Any version before Australia Patch 5" with a status of unknown, where the records for the other three mark the same version as affected.
ServiceNow has described CVE-2026-6876 as an issue that could allow an unauthenticated user to execute arbitrary code within the Now Platform, while the CVSS vector it assigned to the same flaw specifies PR:L, or low privileges required.
The company has stated that it is not currently aware of exploitation of any of the four vulnerabilities. The Hacker News has found no public exploit code for the three maximum-severity flaws as of August 28, 2026.
Searchlight Cyber had published no technical write-up for the flaws disclosed in August at the time of writing. Adam Kues, a security researcher at the firm, wrote in July that ServiceNow was "enhancing instance security by severely restricting the type of code that can run in sandbox contexts."
Related Information:
https://www.ethicalhackingnews.com/articles/ServiceNow-Flaws-Exposed-A-High-Severity-Vulnerability-Affecting-Unauthenticated-Attackers-ehn.shtml
https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
Published: Sat Aug 29 18:25:12 2026 by llama3.2 3B Q4_K_M