[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzq0FG9JRg_EVwv3qtoYMxxKs0ZOgboOEIx9f2GBat8Y":3},{"article":4,"iocs":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"cfdbbc51-3a43-469a-ba6b-8974c7ac93e3","ServiceNow warns of three max severity security vulnerabilities","servicenow-warns-of-three-max-severity-security-vulnerabilities-d78fd3","ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. [...]","ServiceNow has released patches for three critical vulnerabilities in its AI Platform, allowing for code injection, SQL injection, and privilege escalation. These flaws can be exploited by unauthenticated attackers with low complexity. The company also addressed a high-severity sandbox escape vulnerability. While no active exploitation is currently known, past ServiceNow vulnerabilities have been chained and exploited in attacks.","ServiceNow warns of three critical AI Platform vulnerabilities, including code injection and SQL injection flaws.","ServiceNow warns of three max severity security vulnerabilities By Sergiu Gatlan August 28, 2026 06:29 AM 0 ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. The ServiceNow AI Platform (formerly known as the Now Platform) is an enterprise-grade Platform-as-a-Service (PaaS) that helps integrate AI into core enterprise workflows and powers more than 100,000 enterprise AI apps at 85% of all Fortune 500 companies. In a Thursday advisory, the company said it patched its cloud-based platform against the three critical security flaws (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820) and advised customers to secure their self-hosted instances. The first is a code injection vulnerability that can allow attackers to execute arbitrary code, the second stems from a code injection weakness that enables them to escalate privileges, and the third allows threat actors to access or modify instance data through SQL injection attacks. All three security vulnerabilities can be exploited by unauthenticated threat actors in low-complexity attacks that don't require user interaction. On Thursday, ServiceNow also addressed a high-severity sandbox escape security issue (CVE-2026-6876) affecting the same platform that could let attackers with basic privileges gain remote code execution on targeted systems. Release Version Updated Xanadu Patch 11 Hot Fix 7a Yokohama Yokohama Patch 12 Hot Fix 3b Yokohama Patch 13 Hot Fix 4 Zurich Zurich Patch 7b Hot Fix 3 Zurich Patch 8 Hot Fix 5 Zurich Patch 9 Hot Fix 6 Zurich Patch 10 Hot Fix 2m (m-branch) Zurich Patch 10 Hot Fix 3 (standard) Zurich Patch 11 Zurich Patch 12 Australia Australia Patch 2 Hot Fix 3 Australia Patch 3 Hot Fix 2 Australia Patch 3m Australia Patch 4 Australia Patch 5 \"We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so,\" the company said. While ServiceNow didn't flag any of the vulnerabilities patched on Thursday as actively exploited, multiple security flaws in ServiceNow products have been targeted in attacks in recent years. Two years ago, threat actors chained three ServiceNow flaws (CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217) using publicly available exploits to breach private firms and government agencies worldwide in data theft attacks. More recently, in July, threat intelligence company Defused reported that attackers are now exploiting another critical vulnerability (CVE-2026-6875), a pre-auth sandbox escape in the ServiceNow AI Platform. ServiceNow has also privately disclosed a security incident last month in which security researchers or customer-led research used an unauthenticated access flaw via a vulnerable API endpoint to query data from customer instances. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: Critical ServiceNow code execution flaw now exploited in attacksCritical Avada WordPress theme flaw enables zero-click RCECISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayHackers now exploit critical Gitea flaw in code injection attacksHackers breached over 270 Zimbra servers in ongoing attacks","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fservicenow-warns-of-three-max-severity-security-vulnerabilities\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F07\u002F20\u002Fservicenow-headpic.jpg","2026-08-28T10:29:42+00:00","2026-08-28T12:00:29.211477+00:00",9,[18,21],{"name":19,"type":20},"AI Platform","product",{"name":22,"type":23},"ServiceNow","vendor","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":24,"icon":26,"name":27,"slug":28},null,"Vulnerabilities","vulnerabilities",[30,35,37],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":36},{"id":24,"icon":26,"name":27,"slug":28},{"category":38},{"id":39,"icon":26,"name":40,"slug":41},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[43,47,50,53,56,59,61,63],{"type":44,"value":45,"context":46},"cve","CVE-2026-18885","Maximum severity AI Platform vulnerability allowing code injection.",{"type":44,"value":48,"context":49},"CVE-2026-18886","Maximum severity AI Platform vulnerability allowing privilege escalation.",{"type":44,"value":51,"context":52},"CVE-2026-74820","Maximum severity AI Platform vulnerability allowing SQL injection.",{"type":44,"value":54,"context":55},"CVE-2026-6876","High-severity sandbox escape vulnerability in AI Platform.",{"type":44,"value":57,"context":58},"CVE-2024-4879","Previously exploited ServiceNow vulnerability.",{"type":44,"value":60,"context":58},"CVE-2024-5178",{"type":44,"value":62,"context":58},"CVE-2024-5217",{"type":44,"value":64,"context":65},"CVE-2026-6875","Previously exploited pre-auth sandbox escape vulnerability in AI Platform."]