ServiceNow patches three maximum severity flaws that could put enterprise data at risk
Summary
ServiceNow has released patches for three critical vulnerabilities in its AI Platform that could allow attackers to inject code, execute SQL commands, and escalate privileges. These flaws, tracked as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, pose a significant risk to enterprise data. The company is urging self-hosted customers to apply the patches immediately.
IFF Assessment
The discovery and patching of critical vulnerabilities that can lead to data compromise represent bad news for defenders, as they highlight significant risks within enterprise platforms.
Severity
Multiple maximum severity flaws (10/10) allowing unauthenticated arbitrary code execution, SQL injection, and privilege escalation directly impacting confidentiality, integrity, and availability are indicative of a CVSS score of 10.0.
Defender Context
Defenders should prioritize patching these critical vulnerabilities in ServiceNow instances immediately, especially for self-hosted environments. The prevalence of these flaws, even in AI-integrated platforms, underscores the ongoing importance of foundational security practices like secure coding and regular vulnerability management.