ServiceNow closed four critical security vulnerabilities in its AI platform on August 27, 2026. Three of them reach the highest threat level with a CVSS score of 10.0. Unauthenticated attackers could execute arbitrary code without any interaction and gain access to corporate data.
Four vulnerabilities reach CVSS maximum
The company’s security advisory lists four CVE entries. The affected component is the AI Platform, the AI infrastructure through which ServiceNow automates IT, HR, and customer service workflows. All four vulnerabilities can be exploited over the network with little technical effort. An overview of the four vulnerabilities:
- CVE-2026-18885 (CVSS 10.0): A vulnerability in the GraphQL interface allows unauthenticated attackers to execute arbitrary code and modify instance data.
- CVE-2026-18886 (CVSS 10.0): The image upload for system configurations can be abused to manipulate instance data and escalate privileges.
- CVE-2026-74820 (CVSS 10.0): A SQL injection in a dynamic sorting function opens access to the underlying database.
- CVE-2026-6876 (CVSS 8.7): A sandbox escape vulnerability in the Now Platform sandbox allows code execution but requires low privileges.
For the three most severe vulnerabilities, no credentials or user interaction are needed. Hosted cloud instances received the fixes automatically, while operators of self-hosted installations must manually apply the hotfixes for the versions Xanadu, Yokohama, Zurich, and Australia. At the time of reporting, there was no publicly available exploit code according to research from several security media.
ServiceNow’s AI platform controls central company processes
The AI Platform consolidates IT support, HR processes, and customer contacts into a single AI-driven interface – the German industrial giant Siemens, for example, uses the underlying Now Platform for its internal IT support. This very interconnection makes the four vulnerabilities risky: those who compromise the platform could potentially access connected credentials, tokens, and partner systems, as ServiceNow often acts as a central hub between departments and external service providers, according to CSO Online.
A precedent shows that such vulnerabilities are exploited in reality: another critical ServiceNow vulnerability, CVE-2026-6875, was actively attacked as early as July 2026. Similar patterns have also emerged in other business platforms recently – just in August, security researchers found a chain of two vulnerabilities with full server access in Microsoft SharePoint. The British health service NHS England responded to the new ServiceNow vulnerabilities with its own warning to connected facilities. ServiceNow itself states that it is not aware of any exploitation of the new vulnerabilities so far. No public exploit code is available at the time of reporting.
It will be crucial whether security researchers publish exploit code in the coming days. So far, the risk remains theoretical, but once functional attack code circulates, unpatched, self-hosted instances are likely to become targets quickly. It also remains open how many companies will update their on-premise installations in a timely manner, as previous ServiceNow vulnerabilities often remained unpatched for months in practice.


