ServiceNow Patches Three Critical Flaws in AI Platform
ServiceNow releases security patches for three new maximum-severity vulnerabilities in its AI Platform, warning customers to apply updates immediately. The flaws, tracked as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, expose the platform to code injection, privilege escalation, and SQL injection attacks. The company says its cloud-based platform is already patched and advises customers running self-hosted instances to secure them right away.
All three vulnerabilities can be exploited by unauthenticated attackers in low-complexity attacks that require no user interaction. The first flaw allows attackers to execute arbitrary code, the second lets them escalate privileges through a code injection weakness, and the third enables threat actors to access or modify instance data via SQL injection. ServiceNow also patches a high-severity sandbox escape flaw, CVE-2026-6876, which could allow attackers with basic privileges to achieve remote code execution.
The patches span multiple release versions, including Xanadu, Yokohama, Zurich, and Australia, with specific hotfixes available for each. ServiceNow says it is not currently aware of malicious exploitation of these flaws, but stresses that customers should promptly apply updates or upgrade to a patched release. The company's products have been targeted in the past, with attackers chaining three ServiceNow vulnerabilities two years ago to breach private firms and government agencies worldwide.