ServiceNow Patches Three Maximum-Severity AI Platform Vulnerabilities
ServiceNow has fixed three critical vulnerabilities in its AI Platform that could allow unauthenticated code injection, SQL injection, and privilege escalation, along with a high-severity sandbox escape.

ServiceNow has issued security patches for three maximum-severity vulnerabilities in its AI Platform, the enterprise platform-as-a-service formerly known as Now Platform. In a Thursday advisory, the company said it has fixed the issues in its cloud-based service and is urging customers who run self-hosted instances to update immediately. The platform is widely used to embed AI into core business workflows and, according to the report, powers more than 100,000 enterprise AI applications at 85 percent of Fortune 500 companies.
The three critical flaws are identified as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. ServiceNow describes the first as a code injection vulnerability that can lead to arbitrary code execution. The second arises from a code injection weakness that allows attackers to escalate their privileges. The third enables SQL injection, which could let an attacker access or modify data stored in an instance. All three vulnerabilities can be exploited by unauthenticated threat actors in low-complexity attacks that require no user interaction, meaning remote attackers need no existing credentials to attempt exploitation.
Additionally, ServiceNow patched a high-severity sandbox escape flaw, tracked as CVE-2026-6876, affecting the same platform. That vulnerability could potentially allow an attacker with basic privileges to achieve remote code execution on targeted systems.
The company said it is not currently aware of malicious exploitation against ServiceNow instances, and it recommends that customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so. However, the advisory did not list any temporary workarounds or alternative mitigations. While none of the newly fixed flaws were flagged as actively exploited, ServiceNow products have been targeted repeatedly in recent years. For example, two years ago, attackers chained three ServiceNow vulnerabilities using public exploits to breach private firms and government agencies worldwide in data theft operations. More recently, in July, threat intelligence company Defused reported active exploitation of a separate critical pre-authentication sandbox escape in the AI Platform, CVE-2026-6875. ServiceNow also privately disclosed a security incident last month in which researchers or customer-led research used an unauthenticated access flaw through a vulnerable API endpoint to query data from customer instances.
Given the history of attacks against ServiceNow platforms and the severity of the newly fixed issues, organizations with self-hosted deployments should treat patching as urgent. Cloud customers are already protected by the vendor's patch, but self-managed environments remain exposed until updates are applied. Administrators should apply the relevant updates or upgrade to a patched release as ServiceNow advised.