ServiceNow Tackles Maximum-Severity Flaws
Patches cover three critical code injection bugs and a sandbox escape in the Now Platform.
ServiceNow has pushed out fixes for four vulnerabilities in its platform, three of which carry the maximum possible CVSS severity score of 10/10. The flaws, which include code injection, SQL injection, and an access control weakness, could give attackers deep access to instance data and underlying systems, according to an advisory from the company.
Flaws at a Glance
The first critical bug, tracked as CVE-2026-18885, is a code injection vulnerability that allows an attacker to execute arbitrary code in the ServiceNow platform under certain circumstances. ServiceNow notes in its advisory that an attacker could exploit the weakness to gain access to and potentially modify arbitrary data.
The second critical defect, CVE-2026-18886, is described as an improper access control issue. It could allow an attacker to create or modify arbitrary data and elevate their privileges.
The third critical vulnerability, tracked as CVE-2026-74820, is an SQL injection flaw. It allows an attacker to execute arbitrary SQL statements against the underlying ServiceNow database. According to ServiceNow, an attacker could exploit the bug to “gain access to, or modify, instance data beyond what was intended.”
Authentication Not Required
None of the three critical vulnerabilities requires authentication or user interaction. All three can be exploited in low-complexity attacks, the company said, which means attackers with network access could potentially trigger them without credentials.
The fourth issue, tracked as CVE-2026-6876 (CVSS score of 8.7), is a high-severity sandbox escape weakness that could be exploited without authentication for code execution within the Now Platform. An attacker could exploit the security defect to gain “more access to the Now Platform than intended,” the company says.
Patches and Hotfixes Rolled Out
ServiceNow says it has rolled out patches for all four vulnerabilities across its hosted instances. The company also released hotfixes for self-hosted instances, encouraging customers to apply them as soon as possible.
The hotfixes are available for ServiceNow’s Xanadu, Yokohama, Zurich, and Australia releases.
Expert Urgency
According to Jason Brown, director of counter fraud operations at iCOUNTER, security teams should prioritize patching their ServiceNow instances, as attackers are quick to exploit newly discovered vulnerabilities. Brown highlighted the risk for self-hosted customers, who must manage the patching process themselves.
Everyone running ServiceNow on their own infrastructure now has to go find, schedule, and apply that patch themselves, and in a lot of organizations that process takes weeks, not days. During those weeks, an unauthenticated attacker with a working exploit for the GraphQL Composite Data API code injection bug or the SQL injection flaw has a real shot at systems that sit next to HR records, vendor onboarding, and finance approvals.
He added, “I spent years chasing fraud operators who specifically target that lag between disclosure and patch adoption, because they know it’s where the easy access is. My advice to any security team running ServiceNow self-hosted right now is simple: don’t wait for your normal patch cycle, treat this one as urgent and confirm it’s applied this week.”
What It Means for You
For organizations running ServiceNow, especially those on self-hosted instances, the window between disclosure and patching is a critical exposure period. The absence of authentication requirements on the critical flaws makes them particularly attractive to attackers, who may move quickly to exploit them before fixes are widely applied.
Given the sensitive nature of data typically managed in ServiceNow environments—HR records, vendor onboarding, finance approvals—the potential impact of a successful exploit is substantial. Brown’s warning underscores the need to treat this patch as an exception to routine maintenance cycles, confirming that hotfixes are applied promptly to close the gap before attackers can take advantage.
Sources
- SecurityWeek Original source
Continue Reading
North Korea's Job Fraud Widens Beyond IT
DPRK workers now target sales, marketing, and healthcare roles, using AI and VPNs to evade detection.
Residential proxies turn media players into attack relays
Plume research shows SuperBox streaming devices open home networks to malware, despite router placement.
AI threatens to outpace enterprise security
OpenAI-led coalition warns AI will compress cyberattack timelines, exposing unfixed enterprise weaknesses.