ServiceNow Patches Three CVSS 10 Flaws In AI Platform Powering 85% Of Fortune 500

ServiceNow patched three maximum-severity vulnerabilities in its AI Platform that let unauthenticated attackers inject code, escalate privileges and run SQL injection across an install base that powers 85% of the Fortune 500.

ServiceNow Patches Three CVSS 10 Flaws In AI Platform Powering 85% Of Fortune 500

ServiceNow on August 27, 2026 pushed emergency patches for three maximum-severity vulnerabilities in the ServiceNow AI Platform, its enterprise Platform-as-a-Service that powers more than 100,000 enterprise AI apps at 85% of Fortune 500 companies — a rare triple CVSS 10.0 disclosure that can be exploited by unauthenticated attackers without user interaction.

Three max-severity CVEs and a bonus RCE

The three critical bugs are CVE-2026-18885 (code injection leading to remote code execution), CVE-2026-18886 (a second code-injection flaw that enables privilege escalation) and CVE-2026-74820 (a SQL-injection weakness that lets attackers read or modify instance data). All three carry a CVSS v4.0 score of 10.0 and are exploitable in low-complexity attacks that require no authentication and no user interaction. ServiceNow also patched CVE-2026-6876, a high-severity sandbox-escape bug in the same platform that could let attackers with basic privileges gain remote code execution.

Fixes across Xanadu, Yokohama, Zurich and Australia

ServiceNow issued patched builds across every currently supported release train: Xanadu Patch 11 Hot Fix 7a; Yokohama Patch 12 Hot Fix 3b and Patch 13 Hot Fix 4; multiple hot fixes for Zurich Patch 7b through Patch 12; and the Australia Patch 2 through Patch 5 series. "We are not currently aware of malicious exploitation against ServiceNow instances," the company said in its advisory, but urged customers to apply appropriate updates immediately. Self-hosted instances are the biggest risk surface: SaaS tenants are patched by the vendor, while on-prem operators must schedule the upgrade themselves.

ServiceNow's global headquarters in Santa Clara, California.

A pattern of ServiceNow exploitation

The disclosure lands in the middle of a rough year for ServiceNow security. In July, Defused reported that attackers were actively exploiting CVE-2026-6875, a pre-auth sandbox escape in the same AI Platform. And two years ago, threat actors chained CVE-2024-4879, CVE-2024-5178 and CVE-2024-5217 to breach private firms and government agencies worldwide in credential-theft attacks. ServiceNow last month also privately disclosed a separate security incident in which an unauthenticated access flaw was used to query data from customer instances.

Why this bug class matters for AI workflows

The ServiceNow AI Platform (rebranded from Now Platform earlier this year) sits at the heart of enterprise AI-agent adoption — hosting agentic workflows, tool-use runtimes and connectors that ServiceNow and its partners have been aggressively pushing into IT, HR and customer operations. A pre-auth RCE against that layer is effectively a pre-auth RCE against the AI agents built on top of it, echoing the concerns raised by OpenAI, Anthropic and 100+ firms warning on AI cyberattacks and the recent NVIDIA-ServiceNow Project Arc desktop AI-agent push. It also arrives as CISA continues to add newly exploited flaws to the KEV catalog, and just days after PaperCut shipped its second emergency patch for an actively exploited zero-day chain.

Customers running self-hosted ServiceNow instances should upgrade or apply the appropriate hot fix immediately, and rotate any credentials that may have been exposed through the AI Platform's connectors.

Reporting based on coverage from BleepingComputer, The Hacker News and ServiceNow's own KB3152242 advisory.

Category: Cyber Security

Tags: AI Security Cybersecurity AI Foundation Models AI Infrastructure CVE AI Security AI Red Teaming

Related Articles