Cybersecurity Blog | RedLegg

Security Bulletin: Multiple Critical Vulnerabilities in ServiceNow AI Platform

Written by RedLegg's Cyber Threat Intelligence Team | 8/28/26, 5:54 PM

About:

CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820 are three critical vulnerabilities affecting the ServiceNow AI Platform, each with a CVSS score of 10.0.

CVE-2026-18885 and CVE-2026-18886 are code injection vulnerabilities that may allow an unauthenticated attacker to execute arbitrary code, access or modify instance data, or escalate privileges under certain circumstances.

CVE-2026-74820 is a SQL injection vulnerability that may allow an unauthenticated attacker to execute arbitrary SQL statements against the underlying database and access or modify instance data beyond intended permissions.

ServiceNow has released updates addressing all three vulnerabilities. No known exploitation has been reported at this time.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.

VULNERABILITIES

Multiple Critical Vulnerabilities in ServiceNow AI Platform


Identifier: CVE-2026-18885, CVE-2026-18886, CVE-2026-74820 
PoC or Exploitation:  No known exploitation across these vulnerabilities at this time.  
CVSS Score: 10.0 (Critical, CVSS v4.0) for each vulnerability


Update / Patch:

ServiceNow has released fixed versions addressing these vulnerabilities together, under a single August 2026 CVE Advisory Notification.
 
Affected versions include:
Customers on any release prior to the fixed versions listed below
 
Fixed versions include:
  • Xanadu Patch 11 Hot Fix 7a
  • Yokohama Patch 12 Hot Fix 3b
  • Yokohama Patch 13 Hot Fix 4
  • Zurich Patch 7b Hot Fix 3
  • Zurich Patch 8 Hot Fix 5
  • Zurich Patch 9 Hot Fix 6
  • Zurich Patch 10 Hot Fix 2m, m-branch
  • Zurich Patch 10 Hot Fix 3, standard
  • Zurich Patch 11
  • Zurich Patch 12
  • Australia Patch 2 Hot Fix 3
  • Australia Patch 3 Hot Fix 2
  • Australia Patch 3m
  • Australia Patch 4
  • Australia Patch 5
 
Customers enrolled in ServiceNow's Patching Program received these updates automatically on hosted instances. Self-hosted customers must apply the updates themselves.
 
ServiceNow Knowledge Base Article KB3152242:
https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3152242


Description:

CVE-2026-18885 is a code injection vulnerability. An unauthenticated user can, in certain circumstances, execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended.
 
CVE-2026-18886 is also described by ServiceNow as a code injection vulnerability. An unauthenticated user can, in certain circumstances, create or modify instance data beyond what was intended resulting in privilege escalation.
 
CVE-2026-74820 is a SQL injection vulnerability. An unauthenticated user can, in certain circumstances, execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended.

 

Mitigation Recommendation:

Compare your instance version against the fixed-version table above to determine whether you have already received the update.
 
Self-hosted customers should apply the appropriate patched release immediately.