Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

ServiceNow Patches 3 Critical Code Injection Vulnerabilities

Attackers could exploit the security defects to execute arbitrary code and access or tamper with data.

ServiceNow

ServiceNow has announced patches for four vulnerabilities, including three critical code injection flaws in the ServiceNow AI platform, each with a maximum severity (CVSS score of 10/10).

The first of the critical bugs, tracked as CVE-2026-18885, allows an attacker to execute arbitrary code in the ServiceNow platform under certain circumstances.

An attacker could exploit the weakness to gain access to and potentially modify arbitrary data, ServiceNow notes in its advisory.

The second critical defect, CVE-2026-18886, is described as an improper access control issue. It could allow an attacker to create or modify arbitrary data and elevate their privileges.

Tracked as CVE-2026-74820, the third critical vulnerability is an SQL injection flaw that allows an attacker to execute arbitrary SQL statements against the underlying ServiceNow database.

An attacker could exploit the bug to “gain access to, or modify, instance data beyond what was intended,” ServiceNow says.

Advertisement. Scroll to continue reading.

According to the company, none of the three vulnerabilities requires authentication or user interaction. All three can be exploited in low-complexity attacks.

The fourth issue, tracked as CVE-2026-6876 (CVSS score of 8.7), is a high-severity sandbox escape weakness that could be exploited without authentication for code execution within the Now Platform.

An attacker could exploit the security defect to gain “more access to the Now Platform than intended,” the company says.

ServiceNow says it has rolled out patches for all four vulnerabilities across its hosted instances. The company also released hotfixes for self-hosted instances, encouraging customers to apply them as soon as possible.

The hotfixes are available for ServiceNow’s Xanadu, Yokohama, Zurich, and Australia releases.

According to iCOUNTER director of counter fraud operations Jason Brown, security teams should prioritize patching their ServiceNow instances, as attackers are quick to exploit newly discovered vulnerabilities. 

“Everyone running ServiceNow on their own infrastructure now has to go find, schedule, and apply that patch themselves, and in a lot of organizations that process takes weeks, not days. During those weeks, an unauthenticated attacker with a working exploit for the GraphQL Composite Data API code injection bug or the SQL injection flaw has a real shot at systems that sit next to HR records, vendor onboarding, and finance approvals,” Brown said. 

“I spent years chasing fraud operators who specifically target that lag between disclosure and patch adoption, because they know it’s where the easy access is. My advice to any security team running ServiceNow self-hosted right now is simple: don’t wait for your normal patch cycle, treat this one as urgent and confirm it’s applied this week,” he added. 

Related: Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

Related: CISA Warns of Exploited Gitea Vulnerability

Related: Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

Related: Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.

Naveen Bhateja has been appointed Chief People Officer at HackerOne.

The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.