ServiceNow warns of three max severity security vulnerabilities

ServiceNow warns of three max severity security vulnerabilities
ServiceNow released patches for three maximum-severity ServiceNow AI Platform flaws that could enable code injection, SQL injection, and privilege escalation attacks. The company also fixed a high-severity sandbox escape issue and urged customers to update their self-hosted instances promptly. #ServiceNow #CVE-2026-18885 #CVE-2026-18886 #CVE-2026-74820 #CVE-2026-6876

Keypoints

  • ServiceNow patched three critical AI Platform vulnerabilities.
  • The flaws could enable code injection, SQL injection, and privilege escalation.
  • All three issues can be exploited without authentication or user interaction.
  • ServiceNow also fixed a high-severity sandbox escape bug that could lead to remote code execution.
  • Customers using self-hosted instances are advised to apply updates or upgrade immediately.

Read More: https://www.bleepingcomputer.com/news/security/servicenow-warns-of-three-max-severity-security-vulnerabilities/