7 min read
By: RedLegg's Cyber Threat Intelligence Team
About:
CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820 are three critical vulnerabilities affecting the ServiceNow AI Platform, each with a CVSS score of 10.0.
CVE-2026-18885 and CVE-2026-18886 are code injection vulnerabilities that may allow an unauthenticated attacker to execute arbitrary code, access or modify instance data, or escalate privileges under certain circumstances.
CVE-2026-74820 is a SQL injection vulnerability that may allow an unauthenticated attacker to execute arbitrary SQL statements against the underlying database and access or modify instance data beyond intended permissions.
ServiceNow has released updates addressing all three vulnerabilities. No known exploitation has been reported at this time.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
VULNERABILITIES
Multiple Critical Vulnerabilities in ServiceNow AI Platform
Identifier: CVE-2026-18885, CVE-2026-18886, CVE-2026-74820
PoC or Exploitation: No known exploitation across these vulnerabilities at this time.
CVSS Score: 10.0 (Critical, CVSS v4.0) for each vulnerability
Update / Patch:
- Xanadu Patch 11 Hot Fix 7a
- Yokohama Patch 12 Hot Fix 3b
- Yokohama Patch 13 Hot Fix 4
- Zurich Patch 7b Hot Fix 3
- Zurich Patch 8 Hot Fix 5
- Zurich Patch 9 Hot Fix 6
- Zurich Patch 10 Hot Fix 2m, m-branch
- Zurich Patch 10 Hot Fix 3, standard
- Zurich Patch 11
- Zurich Patch 12
- Australia Patch 2 Hot Fix 3
- Australia Patch 3 Hot Fix 2
- Australia Patch 3m
- Australia Patch 4
- Australia Patch 5
Description:
Mitigation Recommendation: