ServiceNow has released patches for four vulnerabilities, including three critical unauthenticated code injection flaws in its AI platform that could lead to arbitrary code execution, data modification, privilege escalation, and SQL injection attacks. The company also fixed a high-severity sandbox escape issue and urged customers using self-hosted instances to apply the available hotfixes immediately. #ServiceNow #CVE-2026-18885 #CVE-2026-18886 #CVE-2026-74820 #CVE-2026-6876
Keypoints
- ServiceNow patched four vulnerabilities across its platform.
- Three critical flaws allow unauthenticated code injection and SQL injection.
- The issues could enable arbitrary code execution and data theft or modification.
- A sandbox escape bug could give attackers more access to the Now Platform than intended.
- ServiceNow urged customers, especially self-hosted users, to apply hotfixes immediately.
Read More: https://www.securityweek.com/servicenow-patches-3-critical-code-injection-vulnerabilities/