ServiceNow AI Platform Patches Three Critical 10.0 CVSS Vulnerabilities
ServiceNow recently addressed three maximum-severity vulnerabilities residing within its AI Platform. Astonishingly, each individual flaw received a perfect 10.0 rating on the CVSS 4.0 scale. Furthermore, a potential attacker requires absolutely no authentication or user interaction to exploit these weaknesses. In the most severe scenario, a malicious actor could execute arbitrary code or SQL commands, instantly gaining unrestricted access to highly sensitive corporate data.
The Trio of Maximum Severity Flaws
The most dangerous vulnerability, identified as CVE-2026-18885, exists within the GraphQL Composite Data API. This specific error allows an attacker to inject malicious code. Under specific conditions, they can execute this code directly upon the platform without any prior authentication. A successful attack could grant comprehensive access to the entire ServiceNow instance’s data. Consequently, it allows the unauthorized modification of restricted information.
Configuration and SQL Injection Threats
The second vulnerability, designated CVE-2026-18886, involves inadequate access controls during the loading of system configuration images. Under certain circumstances, an unauthenticated user could maliciously create or alter data within the ServiceNow instance. Ultimately, this allows them to successfully elevate their system privileges.
Finally, CVE-2026-74820 presents a severe SQL injection flaw located within the dynamic schema processing mechanism. This vulnerability permits an attacker to transmit arbitrary SQL commands directly to the platform’s database without requiring any authorization. As a devastating result, the attacker possesses the terrifying potential to read or covertly modify critical corporate information.
Remediation and Ongoing Risk
ServiceNow has already proactively installed the necessary patches across all instances hosted within its proprietary cloud infrastructure. The company also distributed the critical updates to partners and clients operating self-hosted ServiceNow deployments. However, administrators managing these local installations must manually apply the corrected versions. These alarming vulnerabilities specifically affect several releases, including Xanadu, Yokohama, Zurich, and Australia. Demonstrating the severity, the Canadian Centre for Cyber Security issued a separate, urgent warning to ServiceNow administrators on August 28th, strongly recommending the immediate installation of all available updates.
The Danger of Easy Exploitation
According to official statements from ServiceNow, investigators have discovered absolutely no evidence indicating active, real-world exploitation of these three new vulnerabilities. Furthermore, as of August 28th, security researchers have not identified any publicly available exploits. However, the maximum CVSS rating reflects more than just the sheer magnitude of potential damage. All three critical problems are readily accessible over the network. They possess a remarkably low exploitation complexity and demand zero elevated privileges or user interaction.
The potential consequences are exceptionally profound primarily due to ServiceNow’s central role within massive organizations. The platform meticulously manages vital IT processes, extensive infrastructure and asset management, workflow automation, and critical information security operations. Therefore, compromising such a foundational node grants an attacker access far beyond a single, isolated application. It potentially exposes data and automated processes inextricably linked to multiple, crucial segments of the entire corporate infrastructure.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.