ServiceNow released fixes for three CVSS 10.0 vulnerabilities in the Now Platform and ServiceNow AI Platform: CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. An unauthenticated attacker could exploit the low-complexity flaws without user interaction to execute arbitrary code, escalate privileges, or run SQL statements to access and modify instance data. The company also addressed CVE-2026-6876, a high-severity sandbox-escape vulnerability that could enable a basic-privileged user to achieve remote code execution.
Affected deployments span the Xanadu, Yokohama, Zurich, and Australia release families, including multiple patch and hot-fix levels. ServiceNow said it has no evidence that the vulnerabilities are being exploited in the wild, but urged customers—especially operators of self-hosted instances—to identify affected versions and apply the relevant hot fixes or upgrade to patched releases immediately.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-857 warning that ServiceNow products were affected by the vulnerabilities disclosed by ServiceNow. It identified affected Xanadu, Yokohama, Zurich, and Australia releases and urged administrators to review advisories and apply available updates.
ServiceNow disclosed CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, each rated CVSSv4 10.0, plus the CVSSv4 8.7 sandbox-escape flaw CVE-2026-6876. It issued fixes across the Xanadu, Yokohama, Zurich, and Australia release families and said it had no evidence of active exploitation.
ServiceNow previously addressed CVE-2026-6875, a pre-authentication AI Platform sandbox-escape vulnerability rated CVSSv4 9.5. Searchlight Cyber reported that exploitation could compromise a ServiceNow instance and potentially affect connected proxy or MID Server infrastructure.
ServiceNow reclassified CVE-2026-6876, an unauthenticated AI Platform sandbox-escape flaw that can enable code execution in the ServiceNow Platform context, from high to critical severity. The company continued to state it was unaware of active exploitation and urged customers to apply available patches.
Reporting associated ServiceNow's pre-authentication sandbox-escape vulnerability CVE-2026-6875 with exploitation attempts after its July 2026 disclosure, indicating attacker interest in the flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
13 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcecysecurity.news
Open sourcesecurityweek.com
Open sourcesocradar.io
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceacn.gov.it
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.