ServiceNow has released security updates addressing four vulnerabilities in its AI Platform, including three critical flaws rated 10.0 out of 10 under CVSS v4. The vulnerabilities could enable attackers to execute arbitrary code, manipulate platform data, escalate privileges, or directly interact with the underlying database.
The affected platform is used to support enterprise workflows and AI-powered applications. ServiceNow says 85% of Fortune 500 companies rely on its platform, making vulnerabilities that cross application and data boundaries particularly relevant to enterprise security teams.
The most severe issue, tracked as CVE-2026-18885, is a code injection vulnerability in the GraphQL Composite Data API. Under certain conditions, an attacker without authentication could execute arbitrary code within the ServiceNow platform and gain access to, or alter, instance data beyond the permissions intended by the platform. The CVE record credits Adam Kues of Assetnote with discovering the vulnerability.
CVE-2026-18886, also rated CVSS 10.0, involves improper access controls in the system configuration image upload processor. The flaw could allow an unauthenticated user, under certain circumstances, to create or modify instance data and subsequently escalate privileges. Kevin Gervot of Assetnote is credited as the vulnerability's finder.
The third maximum-severity issue, CVE-2026-74820, is an SQL injection vulnerability. An attacker could exploit the weakness to submit arbitrary SQL statements to the underlying ServiceNow database, potentially exposing or modifying instance information outside the access boundaries established by the platform. The CVE record classifies the flaw as CWE-89, or improper neutralization of special elements used in an SQL command.
All three critical vulnerabilities have network attack vectors, low attack complexity, require no privileges and require no user interaction according to their CVSS v4 metrics. CISA's vulnerability enrichment also currently categorizes the three as automatable with total technical impact, while their records state that no exploitation has been observed.
The fourth vulnerability, CVE-2026-6876, carries a CVSS v4 score of 8.7 and concerns a sandbox escape in the Now Platform. Successful exploitation could allow code execution within the platform and provide an attacker with more access than intended. The published CVSS vector lists low privileges as required and no user interaction, so security teams should assess the flaw according to their deployment and access configuration rather than treating it as identical to the three unauthenticated CVSS 10 vulnerabilities.
ServiceNow has applied security updates to its hosted instances and made fixes available to partners and customers operating self-hosted deployments. The vulnerabilities affect the Xanadu, Yokohama, Zurich and Australia release branches, with patched versions including Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b or Patch 13 Hot Fix 4, and multiple Zurich and Australia patch levels. Administrators should compare their exact instance version against ServiceNow's advisory before considering remediation complete.
The urgency is particularly relevant for organizations managing ServiceNow themselves. Unlike vendor-hosted environments where ServiceNow can deploy security updates directly, self-hosted customers must identify the affected release, obtain the appropriate hotfix and complete their own change and validation process.
Security practitioners have also warned that this remediation gap can provide attackers with an opportunity to target newly disclosed enterprise vulnerabilities before organizations complete their patch cycles. Jason Brown, director of counter-fraud operations at iCOUNTER, urged organizations running self-hosted ServiceNow deployments to treat the fixes as an immediate priority rather than waiting for their routine maintenance window.
ServiceNow has advised customers to apply the available updates promptly. The company also states that it is not currently aware of malicious exploitation of these vulnerabilities, but the combination of remote attack paths, code execution and access to enterprise data makes rapid remediation important while public information about the flaws remains limited.








