CVE Tools
Back to feed
Patch released ServiceNow AI Platform cloud ServiceNow rce

ServiceNow warns of three max severity security vulnerabilities

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

ServiceNow has issued security updates for three maximum-severity vulnerabilities affecting its AI Platform, addressing weaknesses that enable code injection, SQL injection, and privilege escalation. These defects (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820) are exploitable by unauthenticated attackers without user interaction, posing significant risks to enterprise environments relying on the platform. While no active exploitation has been confirmed for these specific issues, the company urges immediate patch application for self-hosted instances.