ServiceNow has issued patches for four security vulnerabilities in its AI Platform, with three receiving the maximum possible severity rating of 10.0 on the CVSS scoring system. The flaws, disclosed in an advisory published August 27, 2026, could allow attackers with no authentication to execute code, access sensitive data, or escalate privileges under certain conditions. The company deployed fixes to its hosted instances and made updates available to partners and self-hosted customers, leaving organizations running their own systems responsible for applying the patches themselves.
The three maximum-severity vulnerabilities include CVE-2026-18885, a code injection flaw in the GraphQL Composite Data API that could let an unauthenticated user run arbitrary code and access or alter instance data; CVE-2026-18886, an improper access control issue in the system configuration image upload processor that could enable an unauthenticated user to create or modify instance data and escalate privileges; and CVE-2026-74820, a SQL injection vulnerability reachable through a dynamic schema ORDER BY clause that could allow an unauthenticated user to run arbitrary SQL statements against the underlying database. The fourth flaw, CVE-2026-6876, is a sandbox escape rated 8.7 that could permit an unauthenticated user to execute arbitrary code within the Now Platform. All three 10.0-rated flaws share the same CVSS vector, describing network-reachable attacks of low complexity requiring no privileges or user interaction, with high impact to confidentiality, integrity, and availability in both the vulnerable component and connected systems.
ServiceNow said in each of the four vulnerability records that it's not currently aware of exploitation. A ServiceNow spokesperson told The Hacker News the company has provided updates and patches to address the issues and encouraged self-hosted and hosted customers to apply the relevant fixes if they haven't already done so, adding that the company will continue working directly with customers needing assistance. The advisory follows CVE-2026-6875, a pre-authentication sandbox escape in the same platform reported by Searchlight Cyber on April 1, 2026, for which ServiceNow published an advisory on July 13. Threat intelligence firm Defused said days after the July advisory that it observed in-the-wild exploitation of CVE-2026-6875, then issued a correction stating the captured payload matched Searchlight Cyber's published proof-of-concept exploit.
The 10.0 severity ratings are ServiceNow's own, as the company serves as the CVE Numbering Authority for its products. Since April 15, 2026, NIST has enriched only vulnerabilities appearing in CISA's Known Exploited Vulnerabilities catalog, affecting federal government software, or designated critical under Executive Order 14028. None of the four flaws appeared in the catalog as of August 28, 2026, leaving ServiceNow's assessments as the only severity ratings on record. ServiceNow rated all three new maximum-severity flaws at low attack complexity, while it scored the sandbox escape reported exploited in July at 9.5 under the same scoring system version, with every metric identical except attack complexity, which it set to high. The affected versions span the Xanadu, Yokohama, Zurich, and Australia releases, with specific patch levels required for remediation. The Hacker News found no public exploit code for the three maximum-severity flaws as of August 28, 2026, and Searchlight Cyber had published no technical write-up for the August-disclosed flaws at the time of writing.
The gap between ServiceNow's maximum-severity ratings and the absence of independent validation raises questions about how organizations should prioritize patch deployment in an environment where third-party severity assessments are increasingly scarce. With self-hosted customers bearing sole responsibility for applying fixes and proof-of-concept exploits potentially available for similar vulnerabilities, enterprises face difficult decisions about maintenance windows without the usual external risk signals.

