ServiceNow on August 27, 2026 pushed emergency patches for three maximum-severity vulnerabilities in the ServiceNow AI Platform, its enterprise Platform-as-a-Service that powers more than 100,000 enterprise AI apps at 85% of Fortune 500 companies — a rare triple CVSS 10.0 disclosure that can be exploited by unauthenticated attackers without user interaction.
Three max-severity CVEs and a bonus RCE
The three critical bugs are CVE-2026-18885 (code injection leading to remote code execution), CVE-2026-18886 (a second code-injection flaw that enables privilege escalation) and CVE-2026-74820 (a SQL-injection weakness that lets attackers read or modify instance data). All three carry a CVSS v4.0 score of 10.0 and are exploitable in low-complexity attacks that require no authentication and no user interaction. ServiceNow also patched CVE-2026-6876, a high-severity sandbox-escape bug in the same platform that could let attackers with basic privileges gain remote code execution.
Fixes across Xanadu, Yokohama, Zurich and Australia
ServiceNow issued patched builds across every currently supported release train: Xanadu Patch 11 Hot Fix 7a; Yokohama Patch 12 Hot Fix 3b and Patch 13 Hot Fix 4; multiple hot fixes for Zurich Patch 7b through Patch 12; and the Australia Patch 2 through Patch 5 series. "We are not currently aware of malicious exploitation against ServiceNow instances," the company said in its advisory, but urged customers to apply appropriate updates immediately. Self-hosted instances are the biggest risk surface: SaaS tenants are patched by the vendor, while on-prem operators must schedule the upgrade themselves.

A pattern of ServiceNow exploitation
The disclosure lands in the middle of a rough year for ServiceNow security. In July, Defused reported that attackers were actively exploiting CVE-2026-6875, a pre-auth sandbox escape in the same AI Platform. And two years ago, threat actors chained CVE-2024-4879, CVE-2024-5178 and CVE-2024-5217 to breach private firms and government agencies worldwide in credential-theft attacks. ServiceNow last month also privately disclosed a separate security incident in which an unauthenticated access flaw was used to query data from customer instances.
Why this bug class matters for AI workflows
The ServiceNow AI Platform (rebranded from Now Platform earlier this year) sits at the heart of enterprise AI-agent adoption — hosting agentic workflows, tool-use runtimes and connectors that ServiceNow and its partners have been aggressively pushing into IT, HR and customer operations. A pre-auth RCE against that layer is effectively a pre-auth RCE against the AI agents built on top of it, echoing the concerns raised by OpenAI, Anthropic and 100+ firms warning on AI cyberattacks and the recent NVIDIA-ServiceNow Project Arc desktop AI-agent push. It also arrives as CISA continues to add newly exploited flaws to the KEV catalog, and just days after PaperCut shipped its second emergency patch for an actively exploited zero-day chain.
Customers running self-hosted ServiceNow instances should upgrade or apply the appropriate hot fix immediately, and rotate any credentials that may have been exposed through the AI Platform's connectors.
Reporting based on coverage from BleepingComputer, The Hacker News and ServiceNow's own KB3152242 advisory.
