Unauthenticated RCE, Privilege Escalation, and SQL Injection in ServiceNow AI Platform: Three CVSS 10.0 Vulnerabilities
1. Basic Information Article Title : ServiceNow Patches 3 Critical Code Injection Vulnerabilities Source : SecurityWeek Publication Date : 2026-08-31 Original Article : SecurityWeek Related Sources : ServiceNow August 2026 CVE Advisory , BleepingComputer Related Malware, Threat Groups, CVEs, Products : CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, CVE-2026-6876, ServiceNow AI Platform, Now…
ServiceNow has released patches for three critical code injection vulnerabilities, an access control flaw, and SQL injection in their AI Platform. The vulnerabilities, listed as CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, and CVE-2026-6876, could allow an attacker to execute arbitrary code, manipulate data, escalate privileges, and compromise the underlying database. These flaws were exploitable remotely without authentication, highlighting the urgency of the service provider's response.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.