Critical Alert 6 Active Exploits Detected Today

CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability →
CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability →
CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability →
CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability →
CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability →
CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability →
Powered by CVE Watchtower
×
August 28, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-18886NVD

Vulnerability Summary

ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation. 





ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of exploitation against ServiceNow instances. 



We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Severity Level
UNKNOWN
Published Date
Aug 27, 2026
Last Modified
Aug 27, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
N/A