Improper Access Control (Privilege Escalation) in ServiceNow AI Platform
CVE-2026-18886 is an improper access control vulnerability (CWE-284) in the ServiceNow AI Platform that, in certain circumstances, allows an unauthenticated remote user to create or modify instance data beyond what was intended. Because the flaw is reachable over the network with no privileges or user interaction required, an attacker who meets the advisory's conditions can manipulate instance data and achieve privilege escalation. Successful exploitation carries high impact to the confidentiality, integrity, and availability of the affected instance (CVSS 4.0 score of 10.0). Customers running affected ServiceNow AI Platform releases are potentially affected; ServiceNow has already deployed the security update to hosted instances, while self-hosted customers and partners must apply the provided update themselves. No exploitation has been observed to date (EPSS 0.2%, not listed in CISA KEV, no public proof-of-concept).
· ServiceNow AI Platformlarge
Unauthenticated SQL Injection in ServiceNow AI Platform
CVE-2026-74820 is a critical (CVSS 4.0: 10.0) SQL injection flaw (CWE-89) in the ServiceNow AI platform that an unauthenticated attacker can, in certain circumstances, trigger remotely over the network. Successful exploitation allows arbitrary SQL statements to be executed against the instance's underlying database, giving the attacker access to or the ability to modify instance data beyond what was intended, with the CVSS scoring indicating high impact to confidentiality, integrity, and availability. Any organization running an unpatched ServiceNow instance is affected, but ServiceNow has already deployed the security update to its hosted instances, so remaining exposure is concentrated among self-hosted customers and partners who must apply the provided update themselves. There is currently no known malicious exploitation: EPSS assigns a 0.2% probability of exploitation within 30 days, the flaw is not in CISA KEV, and no public proof-of-concept is known.
· ServiceNow AI platformmass
Unauthenticated Sandbox Escape Allows Code Execution in ServiceNow AI Platform
CVE-2026-6876 is a sandbox escape in the ServiceNow AI Platform (CWE-94, CWE-693, CWE-1284) that allows an unauthenticated, network-based attacker to execute arbitrary code within the platform. Triggering requires no privileges and no user interaction, consistent with the CVSS 4.0 base of 10.0 (AV:N/PR:N/UI:N with high impact across confidentiality, integrity, and availability). Successful exploitation grants arbitrary code execution inside the platform and potentially more access to the ServiceNow AI Platform than intended. All deployments of the ServiceNow AI Platform are affected: ServiceNow has already deployed the remediation to its hosted (SaaS) instances and has provided the update to partners and self-hosted customers. ServiceNow is not currently aware of malicious exploitation, and no public proof-of-concept is known.
· ServiceNow AI Platformlarge
Unauthenticated Code Injection in ServiceNow AI Platform (CVSS 10.0)
ServiceNow has remediated an unauthenticated code injection vulnerability (CWE-94) in the ServiceNow AI platform, scored a maximum 10.0 in CVSS 4.0, exploitable over the network with no privileges and no user interaction. An attacker can trigger it, in certain circumstances, via crafted input to an affected instance, gaining the ability to execute arbitrary code on the platform and access or modify instance data beyond intended permission boundaries. All customers running the affected platform are in scope: ServiceNow has already deployed the fix to hosted instances, while partners and self-hosted customers must apply the provided update or upgrade to a patched release. Related reporting indicates this is one of three CVSS 10.0 ServiceNow flaws disclosed together that could allow unauthenticated code and SQL execution, though specific affected version ranges are not listed in the advisory. There is no public proof-of-concept, the flaw is not in CISA's KEV, EPSS is low (0.4% in 30 days), and ServiceNow states it is not currently aware of malicious exploitation.
· ServiceNow AI platformmass
Unauthenticated Remote Code Execution in ServiceNow AI Platform
ServiceNow has patched a critical, unauthenticated remote code execution vulnerability (CWE-94, code injection) in the ServiceNow AI platform that is reachable over the network without credentials or user interaction, though exploitation requires certain circumstances to be met (CVSS 4.0 attack complexity is high). A remote attacker who successfully triggers the flaw can execute code within the ServiceNow platform, with potentially high impact on the confidentiality, integrity, and availability of the instance and its data. Both ServiceNow-hosted (SaaS) instances and self-hosted customer and partner deployments are affected; hosted instances were fixed via a centrally deployed security update, while self-hosted customers and partners must apply the provided security updates or patched family releases themselves. ServiceNow's advisory states it was not initially aware of exploitation, but subsequent security reporting indicates this pre-auth RCE has been exploited in the wild. There is no known public proof-of-concept and the flaw is not yet in CISA's KEV catalog, but EPSS assigns a 77.6% probability of exploitation within 30 days.
· ServiceNow AI Platform (hosted/SaaS instances) · ServiceNow AI Platform (self-hosted customer and partner deployments)mass