T

Threats

ServiceNow fixes three critical AI Platform vulnerabilities

ServiceNow published an advisory on 27 August 2026 for three critical vulnerabilities affecting the ServiceNow AI Platform. All three issues have a CVSS v4.0 score of 10.0 and can be exploited by an unauthenticated attacker under certain circumstances.

The vulnerabilities could allow arbitrary code execution, privilege escalation, and SQL injection. Successful exploitation could expose or alter instance data beyond intended access controls.

ServiceNow deployed security updates to hosted instances and supplied updates to partners and self-hosted customers. The vendor is not currently aware of malicious exploitation against ServiceNow instances.


Overview

  • Vendor: ServiceNow

  • Product: ServiceNow AI Platform

  • CVEs: CVE-2026-18885, CVE-2026-18886, CVE-2026-74820

  • Severity: Critical

  • CVSS: 10.0 for each vulnerability

  • Publication date: 27 August 2026

  • Exploitation status: ServiceNow is not currently aware of malicious exploitation against its instances


Affected Versions

The following version information applies to all three CVEs in the August 2026 ServiceNow advisory.

Xanadu

  • Affected: Versions earlier than Xanadu Patch 11 Hot Fix 7a

  • Fixed: Xanadu Patch 11 Hot Fix 7a or later

  • Not affected: The vendor advisory does not separately list unaffected versions or configurations

  • Source: ServiceNow August 2026 CVE Advisory Notification

Yokohama

  • Affected: Versions earlier than Yokohama Patch 12 Hot Fix 3b, or earlier than Yokohama Patch 13 Hot Fix 4 on the Patch 13 branch

  • Fixed: Yokohama Patch 12 Hot Fix 3b or later, and Yokohama Patch 13 Hot Fix 4 or later

  • Not affected: The vendor advisory does not separately list unaffected versions or configurations

  • Source: ServiceNow August 2026 CVE Advisory Notification

Zurich

  • Affected: Versions earlier than the applicable updated build for each Zurich branch

  • Fixed: Zurich Patch 7b Hot Fix 3, Zurich Patch 8 Hot Fix 5, Zurich Patch 9 Hot Fix 6, Zurich Patch 10 Hot Fix 2m for the m-branch, Zurich Patch 10 Hot Fix 3 for the standard branch, Zurich Patch 11, or Zurich Patch 12

  • Not affected: The vendor advisory does not separately list unaffected versions or configurations

  • Source: ServiceNow August 2026 CVE Advisory Notification

Australia

  • Affected: Versions earlier than the applicable updated build for each Australia branch

  • Fixed: Australia Patch 2 Hot Fix 3, Australia Patch 3 Hot Fix 2, Australia Patch 3m, Australia Patch 4, or Australia Patch 5

  • Not affected: The vendor advisory does not separately list unaffected versions or configurations

  • Source: ServiceNow August 2026 CVE Advisory Notification


Vulnerability Breakdown

CVE-2026-18885 - Code injection

  • Severity: Critical

  • CVSS: 10.0

  • Description: A code injection vulnerability in the ServiceNow AI Platform could allow an unauthenticated attacker, under certain circumstances, to execute arbitrary code within the ServiceNow platform.

  • Impact: An attacker could gain access to or modify instance data beyond what was intended.

  • Conditions: No authentication is required. ServiceNow states that exploitation is possible in certain circumstances but does not publish further prerequisites in the advisory.

CVE-2026-18886 - Improper access control

  • Severity: Critical

  • CVSS: 10.0

  • Description: An improper access control vulnerability in the ServiceNow AI Platform could allow an unauthenticated attacker, under certain circumstances, to create or modify instance data beyond intended permissions.

  • Impact: Successful exploitation could result in privilege escalation and unauthorised changes to instance data.

  • Conditions: No authentication is required. ServiceNow states that exploitation is possible in certain circumstances but does not publish further prerequisites in the advisory.

CVE-2026-74820 - SQL injection

  • Severity: Critical

  • CVSS: 10.0

  • Description: A SQL injection vulnerability in the ServiceNow AI Platform could allow an unauthenticated attacker, under certain circumstances, to execute arbitrary SQL statements against the instance's underlying database.

  • Impact: An attacker could access or modify instance data beyond what was intended.

  • Conditions: No authentication is required. ServiceNow states that exploitation is possible in certain circumstances but does not publish further prerequisites in the advisory.


Mitigation

  • Verify the instance version against the updated versions in the ServiceNow advisory.

  • For self-hosted deployments, promptly apply the appropriate security update or upgrade to a patched release.

  • For hosted instances, confirm that the ServiceNow-deployed update has been applied.

  • Customers participating in the ServiceNow Patching Program should verify that their instance received the appropriate update.


Summary for IT Teams

  • Products: ServiceNow AI Platform

  • Threat Level: Critical, CVSS 10.0

  • Action Required: Confirm the current release and patch level, then apply the appropriate ServiceNow security update or upgrade to a patched release immediately. Hosted customers should verify the deployed update, while self-hosted customers and partners should complete patching without delay.


Reference


Need Help?

Secure ISS can assist your organisation with assessing exposure, validating ServiceNow instance versions, and planning urgent remediation. Contact the Secure ISS team on 1300 769 460.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.