HackMyIP
← Back to News
2026-08-28 The Hacker News

Three CVSS 10.0 ServiceNow Flaws Expose Instances to RCE and SQL Injection

VulnerabilityCloud SecurityZero-Day

ServiceNow has released patches for four security vulnerabilities in its AI Platform, three of which carry a maximum CVSS score of 10.0 and can be exploited by unauthenticated attackers under certain conditions. The flaws—CVE-2026-18885 (code injection in the GraphQL Composite Data API enabling arbitrary code execution and data tampering), CVE-2026-74820 (a SQL injection vulnerability reachable through a dynamic schema ORDER BY clause), and CVE-2026-18886 (an improper access control bug in the system configuration image upload processor that allows data manipulation and privilege escalation)—all share the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N, signaling network-reachable, low-complexity attacks requiring no privileges or user interaction. A fourth issue, CVE-2026-6876, is a sandbox escape in the Now Platform rated 8.7 that also allows unauthenticated arbitrary code execution.

The company stated it deployed a security update to its hosted instances on August 27, 2026, and provided the corresponding fixes to partners and self-hosted customers—leaving organizations running their own ServiceNow deployments responsible for applying patches promptly. This advisory follows the earlier July 13 disclosure of CVE-2026-6875, a pre-authentication sandbox escape reported to ServiceNow by Searchlight Cyber on April 1, 2026. Threat intelligence firm Defused initially reported observed in-the-wild exploitation of CVE-2026-6875 shortly after the advisory, but later issued a correction confirming the captured payload matched Searchlight Cyber's publicly available proof-of-concept exploit.

A ServiceNow spokesperson told The Hacker News that the company has "not observed evidence that this activity is related to instances that ServiceNow hosts," and urged both self-hosted and ServiceNow-hosted customers to apply the relevant patches immediately. Security teams are advised to inventory all ServiceNow instances, verify patch levels, and review access logs for indicators of compromise—particularly any unexpected GraphQL queries, anomalous file uploads, or suspicious database activity. Admins can use a port scanner to confirm which ServiceNow instances are internet-facing and ensure they are not exposing unnecessary management interfaces.

With multiple unauthenticated, maximum-severity flaws in active disclosure, defenders should also audit credentials associated with ServiceNow accounts using a password checker, enforce MFA on all administrative users, and validate TLS configurations via an SSL/TLS checker to ensure encrypted traffic is properly enforced. The combination of pre-auth RCE, SQL injection, and privilege escalation across four distinct vulnerabilities makes this one of the most severe patch cycles ServiceNow has issued to date.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →