ServiceNow has released security updates for four vulnerabilities, including three rated critical, that could allow unauthenticated attackers to execute code, alter instance data, elevate privileges, or run arbitrary SQL commands against affected environments.
The August 27, 2026 advisory addresses flaws tracked as CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. The issues affect components of the Now Platform and ServiceNow AI platform.
ServiceNow said the vulnerabilities were discovered through its internal security research and responsible disclosure programs, and that each issue was remediated independently.
ServiceNow Patches Critical Flaws
CVE-2026-6876 is a high-severity sandbox escape flaw in the Now Platform. According to ServiceNow, the vulnerability could allow an unauthenticated attacker to execute arbitrary code on the platform and potentially gain access beyond intended security boundaries.
Sandbox escape vulnerabilities are especially significant because they can break the isolation controls designed to restrict code execution and limit access to sensitive platform resources.
The remaining three vulnerabilities are rated critical under the CVSS v4.0 calculator. CVE-2026-18885 is a code injection flaw in the ServiceNow AI platform that could, in certain circumstances, permit unauthenticated remote code execution.
Successful exploitation could allow an attacker to access or modify instance data beyond the permissions intended by the platform. CVE-2026-18886 is another critical code injection vulnerability affecting the ServiceNow AI platform.
Rather than directly describing arbitrary code execution, ServiceNow said the flaw could allow an unauthenticated attacker to create or modify instance data, resulting in privilege escalation.
Such access could enable threat actors to tamper with workflow records, alter business processes, or create conditions for broader access within an affected instance.
The most severe data-layer risk is CVE-2026-74820, a critical SQL injection vulnerability in the ServiceNow AI platform. An unauthenticated attacker could potentially execute arbitrary SQL statements against an instance’s underlying database, gaining unauthorized access to or modifying data.
SQL injection flaws can expose highly sensitive enterprise records, including service-management tickets, identity-related data, workflow configurations, and other operational information stored in a ServiceNow environment.
ServiceNow said customers enrolled in its Patching Program have already received the necessary updates. Organizations should nevertheless verify that their instances are running patched versions.
Fixed releases include Xanadu Patch 11 Hot Fix 7a; multiple Yokohama releases, including Patch 12 Hot Fix 3b and Patch 13 Hot Fix 4; and several Zurich releases through Patch 12.
Australia customers should update to Australia Patch 2 Hot Fix 3, Patch 3 Hot Fix 2, Patch 3m, Patch 4, or Patch 5. Self-hosted ServiceNow customers should promptly apply the relevant update or upgrade to a patched release.
Security teams should also review instance access logs, monitor for unexpected data modifications, and investigate anomalous SQL activity or changes to privileges, particularly in AI-enabled workflows.
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN
