Cyber Security News

Critical ServiceNow Flaws Let Attackers Execute Code and Access Data

ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access sensitive instance data, modify records, or escalate privileges.

The company published its August 2026 CVE advisory on August 27, confirming that the issues were discovered through its internal security research and responsible disclosure programs.

ServiceNow said each vulnerability was remediated independently and urged self-hosted customers to promptly apply the available updates or upgrade to a patched release.

ServiceNow Fixes Critical Flaws

Three of the flaws affect the ServiceNow AI platform. CVE-2026-18885 is a critical code injection vulnerability that could allow an unauthenticated attacker, under certain circumstances, to execute arbitrary code within the ServiceNow platform.

Successful exploitation could also let an attacker access or modify instance data beyond intended permissions. This creates a serious risk for organizations that use ServiceNow to manage IT operations, security workflows, employee requests, customer service records, and enterprise automation.

An attacker who gains unauthorized code execution may be able to abuse the platform’s access to connected business processes and sensitive operational information.

The second critical issue, tracked as CVE-2026-18886, is another code injection flaw in the ServiceNow AI platform. ServiceNow said an unauthenticated attacker could potentially create or alter instance data outside expected authorization limits. This could lead to privilege escalation, enabling an attacker to gain broader access than originally granted.

The third critical vulnerability, CVE-2026-74820, is a SQL injection flaw affecting the ServiceNow AI platform. If exploited, the issue could allow an unauthenticated attacker to execute arbitrary SQL statements against the affected instance’s underlying database.

This could expose sensitive data stored in ServiceNow environments or allow attackers to modify database-backed records. ServiceNow also addressed CVE-2026-6876, a high-severity sandbox escape vulnerability in the Now Platform.

The company said the issue could allow an unauthenticated user to execute arbitrary code on the platform and potentially gain access beyond what was intended.

Sandbox escape flaws are particularly concerning because they can allow attackers to break out of restricted execution environments designed to limit the impact of untrusted code.

Customers enrolled in the ServiceNow Patching Program have already received the appropriate updates. However, organizations should verify that their instances are running a fixed version.

Patched releases include Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b, Patch 13 Hot Fix 4, and later supported fixes; Zurich Patch 7b Hot Fix 3 through Patch 12; and Australia Patch 2 Hot Fix 3 through Patch 5.

Organizations operating self-hosted ServiceNow deployments should treat the three critical AI platform vulnerabilities as a priority.

Security teams should confirm installed versions, apply relevant hotfixes, review privileged access, and monitor instance activity for suspicious data changes, unexpected code execution, or abnormal database queries.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

58 minutes ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

11 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

12 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

12 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago