Skip to main content

ServiceNow Releases Security Advisory for Critical Vulnerabilities in the ServiceNow Now and AI Platforms

Vulnerabilities could enable an unauthenticated attacker to perform arbitrary code execution, privilege escalation, or SQL injection.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Vulnerabilities could enable an unauthenticated attacker to perform arbitrary code execution, privilege escalation, or SQL injection.


Threat details

Introduction

ServiceNow has released security updates to address critical vulnerabilities affecting the ServiceNow Now and AI platforms.

  • CVE-2026-6876 - 'Sandbox Escape' vulnerability - CVSSv4.0 Score: 8.7
  • CVE-2026-18885 - 'Code Injection' vulnerability - CVSSv4.0 Score: 10.0 
  • CVE-2026-18886 - 'Improper Access Control' vulnerability - CVSSv4.0 Score: 10.0 
  • CVE-2026-74820 - 'SQL Injection' vulnerability - CVSSv4.0 Score: 10.0

Remediation advice

Affected organisations are encouraged to review the ServiceNow KB3152242 advisory and apply relevant updates as soon as possible.



CVE Vulnerabilities

Last edited: 28 August 2026 3:07 pm