CVE Tools
Back to feed
Patch released ServiceNow Now Platform rce ServiceNow privilege-escalation

ServiceNow Patches 3 Critical Code Injection Vulnerabilities

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

ServiceNow has issued updates addressing four security defects, including three critical vulnerabilities rated CVSS 10.0 within its AI platform. These high-severity issues—identified as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820—permit unauthenticated remote code execution and privilege escalation without requiring user interaction. Additionally, a high-severity sandbox escape flaw (CVE-2026-6876) was addressed in the same release. The vendor has distributed hotfixes for self-hosted instances across its Xanadu, Yokohama, Zurich, and Australia releases.