ServiceNow patches three critical AI code-injection flaws

ServiceNow released patches for three critical AI platform code-injection vulnerabilities and a high-severity sandbox escape; hosted instances updated and hotfixes posted for self-hosted releases.

ServiceNow has deployed fixes for four vulnerabilities affecting its Now Platform, including three critical code-injection flaws in its AI features and a high-severity sandbox escape. The company reported that patches have been applied to its hosted environment and that hotfixes are available for customers running ServiceNow on their own infrastructure.

The three critical defects carry the maximum CVSS score of 10.0. Tracked as CVE-2026-18885, one is a code-injection vulnerability that can allow an attacker to execute arbitrary code in the platform under certain conditions. CVE-2026-18886 is an improper access control issue that could enable an attacker to create or modify data and escalate privileges. CVE-2026-74820 is an SQL injection that permits execution of arbitrary SQL statements against the ServiceNow database, which could expose or alter instance data beyond intended limits. ServiceNow reported that none of these three require authentication or user interaction and that each can be exploited with low complexity.

The fourth flaw, CVE-2026-6876, has a CVSS score of 8.7 and is described as a sandbox escape that can be exploited without authentication to run code that gains broader access to the Now Platform.

Hotfixes for self-hosted deployments are available for the Xanadu, Yokohama, Zurich and Australia releases. ServiceNow’s hosted customers will receive the update automatically; customers who operate their own instances must download and apply the hotfixes themselves.

Jason Brown, director of counter fraud operations at iCOUNTER, warned that attackers move quickly after vulnerability disclosures and that the interval between disclosure and patching can be exploited. “Everyone running ServiceNow on their own infrastructure now has to go find, schedule, and apply that patch themselves, and in a lot of organizations that process takes weeks, not days. During those weeks, an unauthenticated attacker with a working exploit for the GraphQL Composite Data API code injection bug or the SQL injection flaw has a real shot at systems that sit next to HR records, vendor onboarding, and finance approvals,” he added. “My advice to any security team running ServiceNow self-hosted right now is simple: don’t wait for your normal patch cycle, treat this one as urgent and confirm it’s applied this week.”

Successful exploitation could let attackers access or modify sensitive records, change configuration or approval workflows, or gain elevated privileges within instances, depending on the flaw exploited. ServiceNow’s advisory lists the CVE identifiers and provides mitigation and verification steps. Customers are advised to check their instance release, apply the appropriate hotfix immediately if self-hosted, verify hosted updates have been received, and monitor logs and access controls for unusual activity.

Articles by this author