Critical ServiceNow Flaws Allow Remote Code Execution, Data Access
Key Takeaways ServiceNow has released critical security updates addressing four vulnerabilities across its Now Platform and ServiceNow AI platform. Three of the flaws are rated critical and could...
Key Takeaways
- ServiceNow has released critical security updates addressing four vulnerabilities across its Now Platform and ServiceNow AI platform.
- Three of the flaws are rated critical and could allow unauthenticated remote code execution, unauthorized data access, or privilege escalation.
- The vulnerabilities were discovered internally and through responsible disclosure programs.
- Self-hosted customers are urged to apply updates immediately; patched versions are available.
ServiceNow Addresses Critical Security Flaws
ServiceNow has issued urgent security updates to address four vulnerabilities impacting its core Now Platform and the ServiceNow AI platform. The patches address three critical flaws that could enable unauthenticated attackers to achieve remote code execution, access sensitive instance data, modify records, or escalate privileges within affected systems.
Table Of Content
The company published its August 2026 CVE advisory on August 27, confirming that these security issues were identified through a combination of internal security research and its responsible disclosure initiatives.
According to ServiceNow, each vulnerability has been remediated independently. The platform provider strongly advises self-hosted customers to promptly apply the available security updates or upgrade to a patched release to mitigate potential risks.
Critical Vulnerabilities Detailed
Three of the most severe flaws specifically target the ServiceNow AI platform. CVE-2026-18885 is a critical code injection vulnerability. Under specific conditions, an unauthenticated attacker could exploit this flaw to execute arbitrary code within the ServiceNow platform. Successful exploitation could also grant an attacker unauthorized access to or modification of instance data, extending beyond their intended permissions. This poses a significant risk to organizations leveraging ServiceNow for critical functions such as IT operations, security workflows, employee requests, customer service, and enterprise automation, as unauthorized code execution could compromise connected business processes and sensitive operational information.
Another critical issue, identified as CVE-2026-18886, is also a code injection flaw within the ServiceNow AI platform. ServiceNow stated that this vulnerability could allow an unauthenticated attacker to create or alter instance data outside of authorized limits. This could lead to privilege escalation, enabling an attacker to gain broader access than initially granted within the system.
The third critical vulnerability, CVE-2026-74820, is a SQL injection flaw also affecting the ServiceNow AI platform. Exploitation of this issue could permit an unauthenticated attacker to execute arbitrary SQL statements against the underlying database of an affected instance. Such an attack could lead to the exposure of sensitive data stored in ServiceNow environments or allow attackers to modify database-backed records, posing a severe data integrity and confidentiality risk.
In addition to these critical flaws, ServiceNow also addressed CVE-2026-6876, a high-severity sandbox escape vulnerability found in the core Now Platform. The company indicated that this flaw could allow an unauthenticated user to execute arbitrary code on the platform, potentially gaining access beyond what was initially intended. Sandbox escape vulnerabilities are particularly concerning as they allow attackers to bypass security boundaries designed to isolate and limit the impact of untrusted code, potentially leading to full system compromise.
Patching and Mitigation
Customers enrolled in the ServiceNow Patching Program have already received the necessary updates. However, all organizations are advised to verify that their ServiceNow instances are running a fixed version. Patched releases include Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b, Patch 13 Hot Fix 4, and later supported fixes; Zurich Patch 7b Hot Fix 3 through Patch 12; and Australia Patch 2 Hot Fix 3 through Patch 5.
What You Should Do
- Immediately Apply Updates: Organizations operating self-hosted ServiceNow deployments must prioritize applying the relevant hotfixes or upgrading to a patched release for all affected platforms, especially the ServiceNow AI platform.
- Verify Installed Versions: Confirm that all ServiceNow instances are running one of the officially patched versions.
- Review Privileged Access: Conduct an audit of privileged access within your ServiceNow environment to ensure no unauthorized accounts or permissions exist.
- Monitor Instance Activity: Implement and review monitoring for suspicious data changes, unexpected code execution, or abnormal database queries within your ServiceNow instances.
- Educate Users: Remind users about best practices for identifying and reporting suspicious activity related to ServiceNow.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.