ZeroHour

Search: “ServiceNow Xanadu”

2 stories

ServiceNow security advisory (AV26-857)

Canada's Cyber Centre relays ServiceNow advisories affecting Xanadu, Yokohama, Zurich and Australia releases, urging administrators to patch.

The Canadian Centre for Cyber Security advisory AV26-857 reports that multiple ServiceNow product lines are affected by vulnerabilities: Xanadu prior to Patch 11 Hot Fix 7a, Yokohama prior to Patch 12 Hot Fix 3b and Patch 13 Hot Fix 4, plus multiple Zurich and Australia versions. Administrators are encouraged to review the linked vendor advisories and apply available updates.

Canadian Centre for Cyber Security · 19d agoAdvisory

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

ServiceNow patched four AI Platform flaws, including three pre-authentication CVSS 10.0 issues enabling unauthenticated code execution, SQL injection, and privilege escalation.

ServiceNow released patches on August 27, 2026 for four AI Platform flaws: CVE-2026-18885 (code injection in the GraphQL Composite Data API), CVE-2026-18886 (improper access control enabling privilege escalation), and CVE-2026-74820 (SQL injection), all self-rated CVSS 10.0 and exploitable without authentication, plus CVE-2026-6876, an 8.7 sandbox escape. Updates were deployed to hosted instances, but self-hosted customers must patch affected Xanadu, Yokohama, Zurich, and Australia release lines themselves. ServiceNow says it is not aware of exploitation of the new flaws, and no public exploit code existed as of August 28, 2026; separately, Defused reported in-the-wild exploitation of the earlier CVE-2026-6875 (CVSS 9.5), later noting the captured payload matched Searchlight Cyber's PoC.

The Hacker News · 19d agoVulnerability in the wildCVE-2026-18885CVE-2026-18886CVE-2026-74820+2 CVEs