ServiceNow Patches Three Max-Severity AI Platform Vulnerabilities

Critical flaws allow code injection, SQL injection, and privilege escalation without authentication

edit
By LineZotpaper
Published
Updated
Read Time2 min
Sources2 outlets
ServiceNow has released security patches for three maximum-severity vulnerabilities affecting its AI Platform, warning that unauthenticated attackers could exploit them in low-complexity attacks. The company also addressed a high-severity sandbox escape flaw. The patches come just days after Ubiquiti fixed a similar set of critical vulnerabilities.

ServiceNow on Thursday issued patches for three critical vulnerabilities in its AI Platform (formerly the Now Platform), urging customers to update self-hosted instances promptly. The flaws—tracked as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820—enable code injection, privilege escalation, and SQL injection attacks respectively. All three can be triggered remotely by unauthenticated attackers with low complexity and no user interaction.

Additionally, ServiceNow fixed a high-severity sandbox escape (CVE-2026-6876) that could allow attackers with basic privileges to achieve remote code execution.

The company’s cloud-based platform powers more than 100,000 enterprise AI applications and is used by 85% of Fortune 500 companies. Patches are available across multiple releases, including Xanadu, Yokohama, Zurich, and Australia.

“We are not currently aware of malicious exploitation against ServiceNow instances,” the company said in an advisory. “We recommend customers promptly apply appropriate updates.”

The announcement follows a similar round of patches from Ubiquiti, which last week addressed three maximum-severity vulnerabilities that could also be exploited remotely without privileges. While ServiceNow did not flag any active exploitation for this batch, security issues in its products have been targeted in attacks in recent years.

§

Analysis

Why This Matters

  • ServiceNow's AI Platform is deeply embedded in Fortune 500 enterprise workflows, making these flaws a potential vector for widespread data breaches or service disruption.
  • The vulnerabilities require no authentication or user interaction, lowering the bar for attackers to compromise critical systems.
  • Despite no confirmed exploitation, the patch urgency is high given the platform's scale and past targeting of ServiceNow flaws.

Background

ServiceNow's AI Platform is a PaaS that integrates AI into core enterprise processes. The company has previously addressed critical vulnerabilities, some of which were actively exploited by threat actors to steal credentials. The latest round of patches continues a pattern of fixing high-risk flaws in the platform after discovery.

Key Perspectives

ServiceNow: Has released patches across multiple release families and is actively urging customers to update. It reports no current exploitation but acknowledges the severity. Security Researchers: The combination of code injection, SQL injection, and privilege escalation without authentication makes these vulnerabilities especially dangerous for unpatched systems. Enterprise Customers: Face pressure to patch quickly across potentially large, complex deployments. Many run self-hosted instances, requiring manual update coordination.

What to Watch

  • Whether proof-of-concept exploits or active attacks emerge in the coming days.
  • Speed of patch adoption, particularly among organizations running older release versions.
  • Further advisories from ServiceNow if additional related vulnerabilities are discovered.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.