ServiceNow fixed three maximum-severity security holes in its AI Platform that could let an outsider break into vulnerable instances without logging in. The flaws are CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, affecting cloud and self-hosted deployments; ServiceNow says they enable code injection, privilege escalation, and SQL injection, and also patched a high-severity sandbox escape bug, CVE-2026-6876. The company says it is not aware of active exploitation and published patched release versions for Xanadu, Yokohama, Zurich, and Australia.
Why it matters: Organizations using ServiceNow should treat this as urgent because the bugs are pre-authentication, low-complexity issues in a platform used widely across large enterprises. Customers should apply the listed hotfixes or upgrade immediately, especially for self-hosted instances exposed to the internet.
info@thehackernews.com (The Hacker News)
2026.08.28
98% relevant
This article appears to cover the same ServiceNow disclosure, highlighting the trio of CVSS 10.0 flaws and their impact on AI Platform deployments, likely adding reporting details but not a distinct underlying event.
Sergiu Gatlan
2026.08.28
100% relevant
This article establishes a distinct patch-and-vulnerability story centered on three newly disclosed maximum-severity ServiceNow AI Platform CVEs, separate from the previously tracked CVE-2026-6875 exploitation story.
← Back to all stories