ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Vulnerabilities
ServiceNow has released patches for four severe security vulnerabilities affecting its AI Platform and Now Platform, three of which carry the maximum CVSS score of 10.0. The flaws include unauthenticated code injection via the GraphQL Composite Data API (CVE-2026-18885), a privilege escalation bug in configuration image upload processing (CVE-2026-18886), SQL injection in dynamic ORDER BY clauses (CVE-2026-74820), and a sandbox escape vulnerability (CVE-2026-6876). All four can be exploited remotely without authentication or user interaction, potentially allowing attackers to execute arbitrary code, manipulate databases, escalate privileges, and compromise integration credentials. No active exploitation has been confirmed in the wild as of the disclosure date. Organizations are advised to apply the available hotfixes immediately and restrict external access to ServiceNow administration, API, and upload endpoints.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in