T
Threats
ServiceNow fixes three critical AI Platform vulnerabilities
ServiceNow published an advisory on 27 August 2026 for three critical vulnerabilities affecting the ServiceNow AI Platform. All three issues have a CVSS v4.0 score of 10.0 and can be exploited by an unauthenticated attacker under certain circumstances.
The vulnerabilities could allow arbitrary code execution, privilege escalation, and SQL injection. Successful exploitation could expose or alter instance data beyond intended access controls.
ServiceNow deployed security updates to hosted instances and supplied updates to partners and self-hosted customers. The vendor is not currently aware of malicious exploitation against ServiceNow instances.
Overview
Vendor: ServiceNow
Product: ServiceNow AI Platform
Severity: Critical
CVSS: 10.0 for each vulnerability
Publication date: 27 August 2026
Exploitation status: ServiceNow is not currently aware of malicious exploitation against its instances
Affected Versions
The following version information applies to all three CVEs in the August 2026 ServiceNow advisory.
Xanadu
Affected: Versions earlier than Xanadu Patch 11 Hot Fix 7a
Fixed: Xanadu Patch 11 Hot Fix 7a or later
Not affected: The vendor advisory does not separately list unaffected versions or configurations
Yokohama
Affected: Versions earlier than Yokohama Patch 12 Hot Fix 3b, or earlier than Yokohama Patch 13 Hot Fix 4 on the Patch 13 branch
Fixed: Yokohama Patch 12 Hot Fix 3b or later, and Yokohama Patch 13 Hot Fix 4 or later
Not affected: The vendor advisory does not separately list unaffected versions or configurations
Zurich
Affected: Versions earlier than the applicable updated build for each Zurich branch
Fixed: Zurich Patch 7b Hot Fix 3, Zurich Patch 8 Hot Fix 5, Zurich Patch 9 Hot Fix 6, Zurich Patch 10 Hot Fix 2m for the m-branch, Zurich Patch 10 Hot Fix 3 for the standard branch, Zurich Patch 11, or Zurich Patch 12
Not affected: The vendor advisory does not separately list unaffected versions or configurations
Australia
Affected: Versions earlier than the applicable updated build for each Australia branch
Fixed: Australia Patch 2 Hot Fix 3, Australia Patch 3 Hot Fix 2, Australia Patch 3m, Australia Patch 4, or Australia Patch 5
Not affected: The vendor advisory does not separately list unaffected versions or configurations
Vulnerability Breakdown
CVE-2026-18885 - Code injection
Severity: Critical
CVSS: 10.0
Description: A code injection vulnerability in the ServiceNow AI Platform could allow an unauthenticated attacker, under certain circumstances, to execute arbitrary code within the ServiceNow platform.
Impact: An attacker could gain access to or modify instance data beyond what was intended.
Conditions: No authentication is required. ServiceNow states that exploitation is possible in certain circumstances but does not publish further prerequisites in the advisory.
CVE-2026-18886 - Improper access control
Severity: Critical
CVSS: 10.0
Description: An improper access control vulnerability in the ServiceNow AI Platform could allow an unauthenticated attacker, under certain circumstances, to create or modify instance data beyond intended permissions.
Impact: Successful exploitation could result in privilege escalation and unauthorised changes to instance data.
Conditions: No authentication is required. ServiceNow states that exploitation is possible in certain circumstances but does not publish further prerequisites in the advisory.
CVE-2026-74820 - SQL injection
Severity: Critical
CVSS: 10.0
Description: A SQL injection vulnerability in the ServiceNow AI Platform could allow an unauthenticated attacker, under certain circumstances, to execute arbitrary SQL statements against the instance's underlying database.
Impact: An attacker could access or modify instance data beyond what was intended.
Conditions: No authentication is required. ServiceNow states that exploitation is possible in certain circumstances but does not publish further prerequisites in the advisory.
Mitigation
Verify the instance version against the updated versions in the ServiceNow advisory.
For self-hosted deployments, promptly apply the appropriate security update or upgrade to a patched release.
For hosted instances, confirm that the ServiceNow-deployed update has been applied.
Customers participating in the ServiceNow Patching Program should verify that their instance received the appropriate update.
Summary for IT Teams
Products: ServiceNow AI Platform
Threat Level: Critical, CVSS 10.0
Action Required: Confirm the current release and patch level, then apply the appropriate ServiceNow security update or upgrade to a patched release immediately. Hosted customers should verify the deployed update, while self-hosted customers and partners should complete patching without delay.
Reference
Need Help?
Secure ISS can assist your organisation with assessing exposure, validating ServiceNow instance versions, and planning urgent remediation. Contact the Secure ISS team on 1300 769 460.

