Critical and high severity security vulnerabilities now fixed by ServiceNow

31 Aug 2026

ServiceNow recently fixed three critical and one high severity flaw in its AI platform.

 

Through the blog, we will understand what the flaws are about, the threats posed by them, and what organizations should do to defend against them.

About the vulnerabilities

Vendor + component affected 

CVEs/CVSS Score/Type 

 

 

ServiceNow Inc. + 

 

ServiceNow AI platform 

CVE-2026-18885/10.0/Code Injection 

CVE-2026-18886/10.0/ Improper Access Control 

CVE-2026-74820/10.0/SQL Injection 

CVE-2026-6876/8.7/Sandbox Escape 

What can attackers do with the vulnerabilities?

Vulnerability  

What can an attacker do? 

 

CVE-2026-18885 

 

 

  • Remotely execute arbitrary code 
  • Access sensitive instance data 
  • Modify instance data 
  • Gain control over affected ServiceNow instance functionality 

 

CVE-2026-18886 

  • Create or modify instance data without authorization ‘ 
  • Escalate privileges 
  • Gain access to functionality or resources  

 

CVE-2026-74820 

  • Execute arbitrary SQL statements against underlying ServiceNow instance database 
  • Access or manipulate database information 
  • Cause a compromise of the integrity and confidentiality of ServiceNow instance data 

CVE-2026-6876  

 

Exploit the sandbox escape to execute arbitrary code within the Now platform

Official security guidance

ServiceNow has released security updates addressing these vulnerabilities.

 

Organizations should:

 

  • Apply the applicable ServiceNow security patches/hotfixes immediately.
  • Self-hosted customers should manually apply the updates provided by ServiceNow.
  • ServiceNow-hosted customers should verify that their instances have received the applicable security updates.
  • Review the affected ServiceNow release versions and apply the corresponding fixed patch/hotfix.

 

Affected release information includes:

 

  • Xanadu: Update to Patch 11 Hot Fix 7a or later.
  • Yokohama: Update to Patch 12 Hot Fix 3b or later, or the applicable later patch.
  • Zurich: Update to the applicable fixed Patch/Hot Fix release.
  • Australia: Update to the applicable fixed Patch/Hot Fix release.

SharkStriker’s recommendations

  • Immediately identify all ServiceNow AI Platform / Now Platform instances in the environment.
  • Verify the current ServiceNow release, patch, and hotfix level.
  • Prioritize patching self-hosted instances immediately.
  • Confirm with ServiceNow that hosted instances have received the required security updates.
  • Restrict unnecessary external exposure of ServiceNow administrative interfaces and APIs where technically feasible.
  • Review ServiceNow logs for suspicious unauthenticated requests, unexpected API activity, unauthorized configuration changes, privilege escalation, and unusual database activity.
  • Review integrations and connected systems because a compromised ServiceNow instance could potentially provide access to connected enterprise systems and sensitive business data.

SharkStriker’s actions

  • We have reviewed the publicly available information regarding the ServiceNow vulnerabilities.
  • We have assessed the potential impact of the vulnerabilities on ServiceNow environments.
  • We recommend organizations verify their ServiceNow versions and patch levels against the vendor’s security advisory.
  • Where applicable, we will review available security telemetry for indicators of exploitation or suspicious ServiceNow activity.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE