Three CVSS 10.0 Flaws, Zero Authentication Required: ServiceNow’s Third Critical AI Platform Patch Since June

🚨 CRITICAL VULNERABILITY ALERT — SaaS Platform / Enterprise Workflow Infrastructure: ServiceNow has patched four vulnerabilities in its Now Platform and AI Platform, three of them rated CVSS 10.0 by the company and exploitable by unauthenticated attackers with no user interaction required. This is the third round of critical ServiceNow AI Platform flaws disclosed since June — and the last one was actively exploited in the wild within weeks of disclosure. If you run ServiceNow, self-hosted or cloud-hosted, confirm your patch status today.

Sources: ServiceNow Security Advisory KB3152242 · The Hacker News · BleepingComputer · CSO Online · GBHackers · CyberPress | Advisory published: August 27, 2026 | CVEs: CVE-2026-18885, CVE-2026-18886, CVE-2026-74820 (CVSS 10.0, ServiceNow-assigned) · CVE-2026-6876 (CVSS 8.7, sandbox escape) | Affected versions: Xanadu, Yokohama, Zurich | Authentication required: None for the three CVSS 10.0 flaws | Known exploitation: None reported as of publication for these four; a related July flaw (CVE-2026-6875) was confirmed exploited in the wild | CISA KEV status: Not listed as of August 28, 2026

FieldDetail
CVE-2026-18885CVSS 10.0 — Code injection in the GraphQL Composite Data API. Unauthenticated attacker can execute arbitrary code and access or modify instance data.
CVE-2026-18886CVSS 10.0 — Improper access control in the system configuration image upload processor. Unauthenticated attacker can create or modify instance data, leading to privilege escalation.
CVE-2026-74820CVSS 10.0 — SQL injection reached through a dynamic schema ORDER BY clause. Unauthenticated attacker can execute arbitrary SQL against the instance’s underlying database.
CVE-2026-6876CVSS 8.7, PR:L (low privileges required) — sandbox escape in the Now Platform enabling remote code execution beyond intended security boundaries.
Discovery routeServiceNow’s internal security research and responsible disclosure program; each issue remediated independently
CVE Numbering AuthorityServiceNow itself — the CVSS 10.0 ratings are the company’s own assessment, not an independent NVD score
NVD enrichment statusSince April 15, 2026, NIST enriches only vulnerabilities in CISA’s KEV catalog, affecting federal software, or designated critical under Executive Order 14028 — none of these four currently qualify, leaving ServiceNow’s own rating as the only severity assessment on record
Public exploit codeNone identified as of August 28, 2026
Prior related flawCVE-2026-6875 (CVSS 9.5, pre-auth sandbox escape, patched June 2026) — confirmed under active exploitation by Defused Cyber in July 2026

What happened

On August 27, ServiceNow published advisory KB3152242, addressing four vulnerabilities across its Now Platform and AI Platform. Three carry the company’s maximum CVSS 10.0 rating: CVE-2026-18885, a code injection flaw in the GraphQL Composite Data API that lets an unauthenticated attacker execute arbitrary code and read or alter instance data; CVE-2026-18886, an improper access control issue in the system configuration image upload processor that lets an unauthenticated attacker create or modify instance data in ways that escalate privilege; and CVE-2026-74820, a SQL injection flaw reached through a dynamic schema ORDER BY clause, allowing unauthenticated attackers to run arbitrary SQL statements against the instance’s underlying database. A fourth, high-severity flaw, CVE-2026-6876, is a sandbox escape that requires only low privileges to achieve remote code execution beyond the platform’s intended boundaries.

ServiceNow says all four were found through its own internal security research and responsible disclosure program, and states it is “not currently aware of exploitation” of any of them. Patches are available for the affected Xanadu, Yokohama, and Zurich versions.

Why the CVSS 10.0 labels deserve a second look, not less urgency

ServiceNow is its own CVE Numbering Authority, and as of April 15, 2026, NIST’s National Vulnerability Database only enriches entries for flaws that are already in CISA’s KEV catalog, affect federal government software, or are designated critical under Executive Order 14028. None of these four currently meet that bar, which means ServiceNow’s self-assigned CVSS 10.0 ratings are, for now, the only severity assessment on record. That’s not a reason to discount the score — a vendor rating its own unauthenticated, no-user-interaction RCE and SQL injection flaws at the maximum severity is not a company downplaying risk. It’s a reason to verify independently rather than wait for a second opinion that may not arrive on the usual timeline.

This is the third critical ServiceNow AI Platform disclosure since June — and the last one got exploited fast

This advisory doesn’t stand alone. In June, ServiceNow patched CVE-2026-6875, a CVSS 9.5 pre-authentication sandbox escape in the AI Platform that Searchlight Cyber had reported back in April. By July 21, threat intelligence firm Defused Cyber confirmed that flaw was under active exploitation in the wild — a compromise capable of taking over both the ServiceNow instance and all connected proxy servers. ServiceNow separately disclosed a related incident last month in which researchers used an unauthenticated API endpoint to query customer instance data without authorization.

The pattern across all of these disclosures is consistent: unauthenticated access paths into a platform that enterprises use to store and automate workflows across HR, IT, security operations, and customer data. Whatever the current exploitation status of this week’s four flaws, the June-to-July timeline on CVE-2026-6875 shows how quickly that status can change once technical details start circulating.

Immediate actions for security and infrastructure teams

1. Confirm your ServiceNow instance version against Xanadu, Yokohama, or Zurich and apply KB3152242 immediately if you haven’t already — this applies to both ServiceNow-hosted and self-hosted deployments.

2. Don’t stop at this advisory — verify CVE-2026-6875 is also patched. That June/July flaw is the one with confirmed in-the-wild exploitation; any instance still unpatched against it should be treated as a live incident-response candidate, not a routine patch item.

3. Review access logs on the GraphQL Composite Data API and any AI Platform components for anomalous unauthenticated requests, unexpected SQL error patterns, or unrecognized data modifications predating this disclosure.

4. Audit what data and downstream systems your ServiceNow instance touches. Given the platform’s role in HR, ITSM, and security operations workflows, a successful compromise here has a wider blast radius than the CVE description alone suggests.

5. Don’t rely solely on the absence of a CISA KEV listing to gauge urgency. Under the current NVD enrichment policy, a flaw can be maximally severe and unauthenticated without ever appearing in the catalog — patch based on ServiceNow’s advisory, not KEV status.

What happens next

No public exploit code or confirmed in-the-wild activity has been reported for these four flaws as of this writing, but the June-to-July trajectory of CVE-2026-6875 — quietly patched, then actively exploited within weeks once technical detail spread — is the closest available precedent. Security teams should expect scrutiny of this advisory to increase as researchers dig into the GraphQL Composite Data API root cause, and should treat the current window before public exploit details emerge as the highest-leverage time to patch.

Sources and further reading


DataWater publishes daily cybersecurity threat briefs. Article #22 — August 29, 2026. See also: OpenAI / Hugging Face Agentic AI Incident (Aug 29) · Citrix NetScaler CVE-2026-8452 (Aug 27) · Gitea CVE-2026-60004 (Aug 26).

Similar Posts