Security

ServiceNow closes four critical gaps in AI platform

2 min read

TL;DR Too Long; Didn’t read

ServiceNow closed four critical security vulnerabilities in its AI platform on August 27, 2026, three of which received the highest score of 10.0 on the CVSS scale. Unauthenticated attackers could execute arbitrary code, manipulate database queries, and escalate privileges. Hosted instances received the patches automatically, while self-hosted installations must update manually. According to its own statements, ServiceNow is not aware of any exploitation of the vulnerabilities.

A broken padlock lies in front of a server rack with a ServiceNow logo, spilling sheets covered in zeros and ones Image generated with GPT Image 2

Key takeaways

  • Three of the four gaps reach the CVSS maximum score of 10.0 – no login and no user interaction required.
  • The central AI platform, which manages IT, HR, and customer service workflows for many companies, is affected.
  • ServiceNow automatically patched hosted instances on August 27, 2026; self-hosted installations require a manual update.
  • One gap is in the GraphQL interface, another in the image upload for system configurations.
  • A flaw that was actively exploited in ServiceNow's software in July shows how real the risk is.
  • According to ServiceNow, there are currently no indications of abuse of the new gaps.

ServiceNow closed four critical security vulnerabilities in its AI platform on August 27, 2026. Three of them reach the highest threat level with a CVSS score of 10.0. Unauthenticated attackers could execute arbitrary code without any interaction and gain access to corporate data.

Four vulnerabilities reach CVSS maximum

The company’s security advisory lists four CVE entries. The affected component is the AI Platform, the AI infrastructure through which ServiceNow automates IT, HR, and customer service workflows. All four vulnerabilities can be exploited over the network with little technical effort. An overview of the four vulnerabilities:

  • CVE-2026-18885 (CVSS 10.0): A vulnerability in the GraphQL interface allows unauthenticated attackers to execute arbitrary code and modify instance data.
  • CVE-2026-18886 (CVSS 10.0): The image upload for system configurations can be abused to manipulate instance data and escalate privileges.
  • CVE-2026-74820 (CVSS 10.0): A SQL injection in a dynamic sorting function opens access to the underlying database.
  • CVE-2026-6876 (CVSS 8.7): A sandbox escape vulnerability in the Now Platform sandbox allows code execution but requires low privileges.

For the three most severe vulnerabilities, no credentials or user interaction are needed. Hosted cloud instances received the fixes automatically, while operators of self-hosted installations must manually apply the hotfixes for the versions Xanadu, Yokohama, Zurich, and Australia. At the time of reporting, there was no publicly available exploit code according to research from several security media.

ServiceNow’s AI platform controls central company processes

The AI Platform consolidates IT support, HR processes, and customer contacts into a single AI-driven interface – the German industrial giant Siemens, for example, uses the underlying Now Platform for its internal IT support. This very interconnection makes the four vulnerabilities risky: those who compromise the platform could potentially access connected credentials, tokens, and partner systems, as ServiceNow often acts as a central hub between departments and external service providers, according to CSO Online.

A precedent shows that such vulnerabilities are exploited in reality: another critical ServiceNow vulnerability, CVE-2026-6875, was actively attacked as early as July 2026. Similar patterns have also emerged in other business platforms recently – just in August, security researchers found a chain of two vulnerabilities with full server access in Microsoft SharePoint. The British health service NHS England responded to the new ServiceNow vulnerabilities with its own warning to connected facilities. ServiceNow itself states that it is not aware of any exploitation of the new vulnerabilities so far. No public exploit code is available at the time of reporting.

It will be crucial whether security researchers publish exploit code in the coming days. So far, the risk remains theoretical, but once functional attack code circulates, unpatched, self-hosted instances are likely to become targets quickly. It also remains open how many companies will update their on-premise installations in a timely manner, as previous ServiceNow vulnerabilities often remained unpatched for months in practice.

Frequently asked questions

What is the ServiceNow AI Platform?

It is the AI-driven foundation of the Now Platform and automates IT support, HR processes, and customer service for enterprise customers worldwide.

Have customer data already leaked?

According to ServiceNow, there are currently no indications of abuse of the four gaps. A public attack code is not known so far.

What do companies need to do now?

Customers with hosted cloud instances have already received the patches automatically. Those who operate the platform themselves must manually apply the hotfixes for the affected versions Xanadu, Yokohama, Zurich, or Australia.

Do the new gaps differ from the vulnerability exploited in July?

Yes, these are four standalone, newly discovered flaws in other components of the platform. The vulnerability exploited in July, CVE-2026-6875, had already been closed previously.

How many companies use the affected platform?

ServiceNow does not provide specific user numbers for the AI Platform. Among the known customers of the Now Platform is the German industrial company Siemens.

Sources (5)
  1. ServiceNow Security Advisory KB3152242
  2. ServiceNow warns of three max severity security vulnerabilities – BleepingComputer
  3. Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL – The Hacker News
  4. ServiceNow patches three maximum severity flaws that could put enterprise data at risk – CSO Online
  5. ServiceNow Releases Security Advisory for Critical Vulnerabilities – NHS England Digital

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog