CyberSecurityNews

Critical ServiceNow Flaws Let Attackers Execute Code and Access Data


ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access sensitive instance data, modify records, or escalate privileges.

The company published its August 2026 CVE advisory on August 27, confirming that the issues were discovered through its internal security research and responsible disclosure programs.

ServiceNow said each vulnerability was remediated independently and urged self-hosted customers to promptly apply the available updates or upgrade to a patched release.

ServiceNow Fixes Critical Flaws

Three of the flaws affect the ServiceNow AI platform. CVE-2026-18885 is a critical code injection vulnerability that could allow an unauthenticated attacker, under certain circumstances, to execute arbitrary code within the ServiceNow platform.

Successful exploitation could also let an attacker access or modify instance data beyond intended permissions. This creates a serious risk for organizations that use ServiceNow to manage IT operations, security workflows, employee requests, customer service records, and enterprise automation.

An attacker who gains unauthorized code execution may be able to abuse the platform’s access to connected business processes and sensitive operational information.

The second critical issue, tracked as CVE-2026-18886, is another code injection flaw in the ServiceNow AI platform. ServiceNow said an unauthenticated attacker could potentially create or alter instance data outside expected authorization limits. This could lead to privilege escalation, enabling an attacker to gain broader access than originally granted.

The third critical vulnerability, CVE-2026-74820, is a SQL injection flaw affecting the ServiceNow AI platform. If exploited, the issue could allow an unauthenticated attacker to execute arbitrary SQL statements against the affected instance’s underlying database.

This could expose sensitive data stored in ServiceNow environments or allow attackers to modify database-backed records. ServiceNow also addressed CVE-2026-6876, a high-severity sandbox escape vulnerability in the Now Platform.

The company said the issue could allow an unauthenticated user to execute arbitrary code on the platform and potentially gain access beyond what was intended.

Sandbox escape flaws are particularly concerning because they can allow attackers to break out of restricted execution environments designed to limit the impact of untrusted code.

Customers enrolled in the ServiceNow Patching Program have already received the appropriate updates. However, organizations should verify that their instances are running a fixed version.

Patched releases include Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b, Patch 13 Hot Fix 4, and later supported fixes; Zurich Patch 7b Hot Fix 3 through Patch 12; and Australia Patch 2 Hot Fix 3 through Patch 5.

Organizations operating self-hosted ServiceNow deployments should treat the three critical AI platform vulnerabilities as a priority.

Security teams should confirm installed versions, apply relevant hotfixes, review privileged access, and monitor instance activity for suspicious data changes, unexpected code execution, or abnormal database queries.



Source link