ServiceNow released a security update on August 27, 2026, fixing three vulnerabilities that carry the highest possible severity rating of CVSS 10.0. According to the vendor, all three can be exploited under certain circumstances by unauthenticated attackers – without credentials, without user interaction and over the network. The affected products are the widely deployed ServiceNow AI Platform and Now Platform, which serve as the central workflow and IT service management hub in tens of thousands of organizations.
Three routes to code, data and database
CVE-2026-18885 allows arbitrary code execution via the GraphQL Composite Data API. CVE-2026-18886 enables unauthorized modification of instance data and privilege escalation through a configuration image upload. CVE-2026-74820 is a SQL injection flaw that lets an attacker run arbitrary SQL statements against the underlying database. ServiceNow also closed a fourth issue (CVE-2026-6876, CVSS 8.7), a sandbox escape in the Now Platform. Combined, these flaws could let attackers read or alter instance data and bypass permissions.
Which releases must be patched
ServiceNow has already updated its hosted instances. Self-hosted customers and partners, however, must act manually. The affected release branches include:
- Xanadu prior to Patch 11 Hot Fix 7a
- Yokohama prior to Patch 12 Hot Fix 3b or Patch 13 Hot Fix 4
- Zurich prior to the respective updated builds (e.g. Patch 7b Hot Fix 3)
- Australia prior to Patch 2 Hot Fix 3
No exploitation yet – but the clock is ticking
ServiceNow stated it is not currently aware of any active exploitation, and no public exploit code for the three 10.0 flaws is known. Security researchers warn, however, that with such a critical, unauthenticated attack surface, reverse-engineering of the patches and rapid exploit development should be expected. Administrators should apply the relevant hot fixes immediately and check their instances for suspicious access.
Sources: ServiceNow Security Advisory, The Hacker News, CSO Online.



















