Technology

Four Critical Flaws Found in ServiceNow AI Platform

ServiceNow has disclosed four critical, unauthenticated vulnerabilities in its AI Platform that enable sandbox escape, remote code execution, and SQL injection attacks. Patches are available, and the vendor reports no known exploits at the time of publication.

Written by AI News Editor

(37m ago)

2 min read
A security alert displayed on a monitor in a corporate server room, with warning indicators highlighting a critical software vulnerability
AI-generated illustration · Four Critical Flaws Found in ServiceNow AI Platform - The Planet Times

What happened?

ServiceNow has disclosed four critical, unauthenticated vulnerabilities in its AI Platform, tracked as CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820.

Why it matters

Successful exploitation could allow attackers to escape the sandbox, execute arbitrary code within ServiceNow Platform, and compromise underlying databases via SQL injection.

ServiceNow has disclosed four critical security vulnerabilities in its AI Platform, warning that all four can be exploited without authentication and that successful attacks affect not only the AI Platform itself but also the broader ServiceNow Platform.

The flaws are tracked as CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, and each carries a critical severity rating. The first, CVE-2026-6876, allows an attacker to break out of the sandboxed environment via an unspecified method and subsequently execute arbitrary code within the context of ServiceNow Platform; the vendor had initially rated this flaw as high severity before later upgrading it to critical. Two of the remaining vulnerabilities similarly allow malicious code to reach affected systems.

The fourth flaw, CVE-2026-74820, opens the door to SQL injection attacks, through which an attacker could compromise the underlying database of a targeted instance.

Patches and affected releases

ServiceNow states that, as of the advisory's publication, no attacks exploiting these vulnerabilities are known to it. Customers enrolled in the ServiceNow Patching Programme have already had the relevant fixes applied automatically; the company nevertheless advises all administrators to verify that a patched release is in place. Fixed versions span the Australia, Xanadu, Yokohama, and Zurich release branches, covering releases from Australia Patch 2 Hot Fix 3 through to Zurich Patch 12.

Topics

CybersecuritySoftware Vulnerabilities

Organizations

ServiceNow

Source: Heise

← Home