news.mlab.sh
Back to the feed
vulnerability

ServiceNow Patches 3 Critical Code Injection Vulnerabilities

CriticalCVSS 10.0
Summary

ServiceNow has released patches for four critical vulnerabilities, including three code injection flaws within its AI platform. These flaws could allow attackers to execute arbitrary code, modify data, and gain elevated privileges without authentication. The company urges customers, particularly those running self-hosted instances, to apply the patches immediately to mitigate the risk of exploitation.

ServiceNow has announced patches for four critical vulnerabilities within its platform. The first, CVE-2026-18885, is a code injection flaw that allows an attacker to execute arbitrary code in the ServiceNow platform under certain circumstances, potentially gaining access to and modifying arbitrary data. The second critical defect, CVE-2026-18886, is an improper access control issue, enabling an attacker to create or modify arbitrary data and elevate their privileges. Tracked as CVE-2026-74820, the third critical vulnerability is an SQL injection flaw that allows an attacker to execute arbitrary SQL statements against the underlying ServiceNow database, potentially gaining access to or modifying instance data beyond what was intended.

According to ServiceNow, none of the three vulnerabilities requires authentication or user interaction, and all can be exploited in low-complexity attacks. The fourth issue, tracked as CVE-2026-6876 (CVSS score of 8.7), is a high-severity sandbox escape weakness that could be exploited without authentication for code execution within the Now Platform, allowing an attacker to gain ‘more access to the Now Platform than intended.’

ServiceNow says it has rolled out patches for all four vulnerabilities across its hosted instances. The company also released hotfixes for self-hosted instances, encouraging customers to apply them as soon as possible. The hotfixes are available for ServiceNow’s Xanadu, Yokohama, Zurich, and Australia releases.

Jason Brown, director of counter fraud operations at iCOUNTER, advises security teams to prioritize patching ServiceNow instances due to the potential for attackers to exploit vulnerabilities quickly. He notes that organizations often experience a significant delay between vulnerability disclosure and patch adoption, creating a window of opportunity for attackers to target systems containing sensitive data like HR records, vendor onboarding, and finance approvals. He recommends treating these patches as urgent and applying them this week to minimize risk.

Read the full article at SecurityWeek