ServiceNow released patches for three maximum-severity ServiceNow AI Platform flaws that could enable code injection, SQL injection, and privilege escalation attacks. The company also fixed a high-severity sandbox escape issue and urged customers to update their self-hosted instances promptly. #ServiceNow #CVE-2026-18885 #CVE-2026-18886 #CVE-2026-74820 #CVE-2026-6876
Keypoints
- ServiceNow patched three critical AI Platform vulnerabilities.
- The flaws could enable code injection, SQL injection, and privilege escalation.
- All three issues can be exploited without authentication or user interaction.
- ServiceNow also fixed a high-severity sandbox escape bug that could lead to remote code execution.
- Customers using self-hosted instances are advised to apply updates or upgrade immediately.