August 30, 2026
servicenow.jpg

I show You how To Make Huge Profits In A Short Time With Cryptos!

Swati KhandelwalAug 28, 2026Vulnerability / Cloud Safety

ServiceNow has launched patches for 4 safety flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in sure circumstances, by an unauthenticated attacker.

The corporate stated it deployed a safety replace to hosted cases and offered the replace to its companions and self-hosted clients, which leaves organizations that run their very own cases to use the fixes themselves.

The advisory was revealed on August 27, 2026, and the 4 vulnerabilities are listed beneath –

  • CVE-2026-18885 (CVSS rating: 10.0) – A code injection vulnerability within the GraphQL Composite Information API that might allow an unauthenticated person to execute arbitrary code and achieve entry to, or modify, occasion knowledge
  • CVE-2026-18886 (CVSS rating: 10.0) – An improper entry management vulnerability within the system configuration picture add processor that might allow an unauthenticated person to create or modify occasion knowledge, leading to privilege escalation
  • CVE-2026-74820 (CVSS rating: 10.0) – A SQL injection vulnerability reached by means of a dynamic schema ORDER BY clause that might allow an unauthenticated person to execute arbitrary SQL statements in opposition to the occasion’s underlying database
  • CVE-2026-6876 (CVSS rating: 8.7) – A sandbox escape within the Now Platform that might permit an unauthenticated person to execute arbitrary code

The three maximum-severity flaws share the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, describing a network-reachable assault of low complexity that requires no privileges and no person interplay, and that carries excessive affect to confidentiality, integrity, and availability in each the weak element and the programs linked to it.

The advisory follows CVE-2026-6875, a pre-authentication sandbox escape in the identical platform. Searchlight Cyber reported that flaw to ServiceNow on April 1, 2026. ServiceNow revealed the advisory for it on July 13.

Risk intelligence agency Defused stated days after the July advisory that it was observing in-the-wild exploitation of CVE-2026-6875. It subsequently issued a correction stating that the captured payload matched Searchlight Cyber’s revealed proof-of-concept (PoC) exploit.

“ServiceNow is conscious of a cybersecurity firm’s latest publication concerning exploitation exercise related to a beforehand disclosed safety vulnerability, recognized as CVE-2026-6875,” a ServiceNow spokesperson instructed The Hacker Information. “Primarily based on our investigation up to now, now we have not noticed proof that this exercise is expounded to cases that ServiceNow hosts.”

“We’ve offered updates and patches designed to deal with this concern, and we encourage our self-hosted and ServiceNow-hosted clients to use the related patches in the event that they haven’t already achieved so. As well as, we’ll proceed to work straight with clients who want help in making use of the patches,” the spokesperson stated.

The ten.0 scores are ServiceNow’s personal. The corporate is the CVE Numbering Authority for its merchandise, and since April 15, 2026, NIST has enriched solely vulnerabilities that seem in CISA’s Identified Exploited Vulnerabilities catalog, have an effect on federal authorities software program, or are designated important below Government Order 14028.

Not one of the 4 flaws appeared within the catalog as of August 28, 2026, leaving ServiceNow’s scores as the one severity evaluation on file.

ServiceNow rated all three of the brand new maximum-severity flaws at low assault complexity. It scored the sandbox escape reported exploited in July at 9.5 below the identical model of the scoring system, with each metric equivalent to the three besides assault complexity, which it set to excessive.

ServiceNow lists the next variations as affected in its August advisory –

  • Xanadu – any model earlier than Patch 11 Sizzling Repair 7a
  • Yokohama – any model earlier than Patch 12 Sizzling Repair 3b, and any model earlier than Patch 13 Sizzling Repair 4
  • Zurich – any model earlier than Patch 7b Sizzling Repair 3, Patch 8 Sizzling Repair 5, Patch 9 Sizzling Repair 6, Patch 10 Sizzling Repair 2m (m-branch), Patch 10 Sizzling Repair 3 (normal), Patch 11, or Patch 12
  • Australia – any model earlier than Patch 2 Sizzling Repair 3, Patch 3 Sizzling Repair 2, Patch 3m, Patch 4, or Patch 5

The file for CVE-2026-18886 marks “Any model earlier than Australia Patch 5” with a standing of unknown, the place the data for the opposite three mark the identical model as affected. All 4 set a default product standing of unaffected, so a launch the listing doesn’t title falls exterior the affected set.

ServiceNow describes CVE-2026-6876 as a difficulty that might permit an unauthenticated person to execute arbitrary code throughout the Now Platform, whereas the CVSS vector it assigned to the identical flaw specifies PR:L, or low privileges required.

That vector additionally data no affect to programs past the weak element, not like the three rated 10.0.

ServiceNow stated in every of the 4 data that it’s not at the moment conscious of exploitation. The Hacker Information discovered no public exploit code for the three maximum-severity flaws as of August 28, 2026.

Searchlight Cyber had revealed no technical write-up for the issues disclosed in August on the time of writing. Adam Kues, a safety researcher on the agency, wrote in July that ServiceNow was “enhancing occasion safety by severely proscribing the kind of code that may run in sandbox contexts.”



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *