ServiceNow Releases Security Advisory for Critical Vulnerabilities in the ServiceNow Now and AI Platforms
Vulnerabilities could enable an unauthenticated attacker to perform arbitrary code execution, privilege escalation, or SQL injection.
Summary
Vulnerabilities could enable an unauthenticated attacker to perform arbitrary code execution, privilege escalation, or SQL injection.
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
ServiceNow has released security updates to address critical vulnerabilities affecting the ServiceNow Now and AI platforms.
- CVE-2026-6876 - 'Sandbox Escape' vulnerability - CVSSv4.0 Score: 8.7
- CVE-2026-18885 - 'Code Injection' vulnerability - CVSSv4.0 Score: 10.0
- CVE-2026-18886 - 'Improper Access Control' vulnerability - CVSSv4.0 Score: 10.0
- CVE-2026-74820 - 'SQL Injection' vulnerability - CVSSv4.0 Score: 10.0
Remediation advice
Affected organisations are encouraged to review the ServiceNow KB3152242 advisory and apply relevant updates as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 28 August 2026 3:07 pm