CVE Tools
Back to feed
Patch released ServiceNow AI Platform cloud ServiceNow rce

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

ServiceNow has deployed security updates to address four vulnerabilities in its AI Platform, including three flaws rated CVSS 10.0 that permit unauthenticated attackers to execute arbitrary code or inject SQL. The advisory covers CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, all of which require low complexity and no prior authorization to compromise instance confidentiality and integrity. A fourth flaw, CVE-2026-6876, allows for sandbox escape. Organizations running self-hosted instances must manually apply the relevant hotfixes, such as Patch 11 Hot Fix 7a for Xanadu, while hosted instances have already received the update.