TL;DR
ServiceNow disclosed four vulnerabilities on August 27, 2026. Three carry a maximum CVSS score of 10, including code injection and SQL injection flaws in the ServiceNow AI Platform. Each ServiceNow vulnerability could let an unauthenticated user run code or reach instance data.
- Product: ServiceNow (2 products)
- Vulnerabilities: 4 flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, CVE-2026-6876)
- Highest severity: 10 (Critical · CVSSv4)
- Worst impact: Unauthenticated Remote Code Execution in GraphQL Composite Data API
- Status: No confirmed exploitation yet; patches available
- Action: Update to Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b, Yokohama Patch 13 Hot Fix 4, Zurich Patch 7b Hot Fix 3 (+11) now
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-18885 | 10 | Unauthenticated Remote Code Execution in GraphQL Composite Data API | Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b, Yokohama Patch 13 Hot Fix 4 (+12) | Not exploited |
| CVE-2026-18886 | 10 | Unauthenticated Privilege Escalation via System Configuration Image Upload Processor | Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b, Yokohama Patch 13 Hot Fix 4 (+11) | Not exploited |
Why It Matters
ServiceNow runs core workflows for thousands of large enterprises and governments. An unauthenticated remote flaw at CVSS 10 is about as serious as it gets. This ServiceNow vulnerability set touches code execution, privilege escalation, and database access. Together, these bugs put instance data and platform integrity at risk.
How the Attack Works
The advisory groups four distinct issues. CVE-2026-18885 and CVE-2026-18886 are code injection flaws in the ServiceNow AI Platform. One could “execute arbitrary code,” while the other enables privilege escalation. CVE-2026-74820 is a SQL injection bug that could “execute arbitrary SQL statements against the instance’s underlying database.” CVE-2026-6876 (CVSS 8.7) is a sandbox escape allowing arbitrary code execution. No exploit code appears here.
Affected Versions
The flaws affect the Now Platform and the ServiceNow AI Platform. Fixes span the Xanadu, Yokohama, Zurich, and Australia release families. Customers should compare their instance version against the vendor’s patch table.
Patch and Mitigation
ServiceNow already pushed updates to customers in its Patching Program. Self-hosted customers must act on their own. The vendor recommends they “promptly apply appropriate updates or upgrade to a patched release.” Verify your version first, then patch.
Exploitation Status
ServiceNow reports no active exploitation. The company found the issues through internal research and responsible disclosure. It notes researchers “may publish their findings publicly,” so proof-of-concept code could surface later.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!