← Terug naar overzicht

ServiceNow has released security patches addressing three maximum-severity vulnerabilities in its AI Platform. The vulnerabilities enable code injection, SQL injection, and privilege escalation attacks. All three flaws have been rated at maximum severity, indicating critical risk to organizations using the platform. ServiceNow urged customers to apply the patches immediately. No specific CVE identifiers were mentioned in the article snippet, but the severity and attack vectors suggest significant exposure for enterprise users relying on ServiceNow for IT service management and automation.

Technical details

Three maximum-severity vulnerabilities were patched in the ServiceNow AI Platform (formerly Now Platform), a PaaS used by over 85% of Fortune 500 companies. CVE-2026-18885 is a code injection vulnerability allowing arbitrary code execution. CVE-2026-18886 is a code injection weakness enabling privilege escalation. CVE-2026-74820 allows attackers to access or modify instance data via SQL injection. All three can be exploited by unauthenticated threat actors in low-complexity attacks requiring no user interaction, earning them maximum severity ratings. Additionally, a high-severity sandbox escape vulnerability (CVE-2026-6876) was patched, which allows attackers with basic privileges to achieve remote code execution. ServiceNow states no active exploitation of these new vulnerabilities has been detected. Historical context: In 2024, three chained ServiceNow flaws (CVE-2024-4879, CVE-2024-5178, CVE-2024-5217) were exploited to breach private firms and government agencies. In July, CVE-2026-6875, a pre-auth sandbox escape, was reported as actively exploited. ServiceNow also recently disclosed a separate security incident involving unauthenticated access via a vulnerable API endpoint used to query customer instance data.

Mitigation steps

1. Apply the relevant security patches immediately for your ServiceNow AI Platform release: Xanadu: Patch 11 Hot Fix 7a; Yokohama: Patch 12 Hot Fix 3b or Patch 13 Hot Fix 4; Zurich: Patch 7b Hot Fix 3, Patch 8 Hot Fix 5, Patch 9 Hot Fix 6, Patch 10 Hot Fix 2m, Patch 10 Hot Fix 3, Patch 11, or Patch 12; Australia: Patch 2 Hot Fix 3, Patch 3 Hot Fix 2, Patch 3m, Patch 4, or Patch 5. 2. Self-hosted/on-premise ServiceNow instances must be patched manually by administrators. 3. Cloud-based instances have already been patched by ServiceNow. 4. Monitor for any signs of exploitation including unusual code execution, privilege escalation attempts, or anomalous SQL queries against ServiceNow instances. 5. Review ServiceNow's official advisory at the support portal (KB3152242) for the latest guidance. 6. Ensure all ServiceNow API endpoints are properly secured and access is restricted to authenticated users where possible.

Affected products

  • Patch 10 Hot Fix 2m
  • Patch 10 Hot Fix 3
  • Patch 11
  • Patch 12
  • Patch 3 Hot Fix 2
  • Patch 3m
  • Patch 4
  • Patch 5
  • Patch 8 Hot Fix 5
  • Patch 9 Hot Fix 6
  • ServiceNow AI Platform (Now Platform) - Australia prior to Patch 2 Hot Fix 3
  • ServiceNow AI Platform (Now Platform) - Xanadu prior to Patch 11 Hot Fix 7a
  • ServiceNow AI Platform (Now Platform) - Yokohama prior to Patch 12 Hot Fix 3b / Patch 13 Hot Fix 4
  • ServiceNow AI Platform (Now Platform) - Zurich prior to Patch 7b Hot Fix 3

Related CVE's

  • CVE-2024-4879
  • CVE-2024-5178
  • CVE-2024-5217
  • CVE-2026-18885
  • CVE-2026-18886
  • CVE-2026-6875
  • CVE-2026-6876
  • CVE-2026-74820

Categories

  • Cloud & Virtualization
  • Database & Storage
  • Enterprise Applications
  • Zero-Day Vulnerabilities