ServiceNow on Thursday issued patches for three critical vulnerabilities in its AI Platform (formerly the Now Platform), urging customers to update self-hosted instances promptly. The flaws—tracked as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820—enable code injection, privilege escalation, and SQL injection attacks respectively. All three can be triggered remotely by unauthenticated attackers with low complexity and no user interaction.
Additionally, ServiceNow fixed a high-severity sandbox escape (CVE-2026-6876) that could allow attackers with basic privileges to achieve remote code execution.
The company’s cloud-based platform powers more than 100,000 enterprise AI applications and is used by 85% of Fortune 500 companies. Patches are available across multiple releases, including Xanadu, Yokohama, Zurich, and Australia.
“We are not currently aware of malicious exploitation against ServiceNow instances,” the company said in an advisory. “We recommend customers promptly apply appropriate updates.”
The announcement follows a similar round of patches from Ubiquiti, which last week addressed three maximum-severity vulnerabilities that could also be exploited remotely without privileges. While ServiceNow did not flag any active exploitation for this batch, security issues in its products have been targeted in attacks in recent years.