Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Why Iceland Chose Fish Over European Alliances

    August 31, 2026

    Guest opinion: Big Tech wants Wisconsin land for data centers. Voters are saying ‘Yeah, no.’

    August 31, 2026

    Did Muslim cashier demand Christian boy remove cross necklace? Here’s the truth

    August 31, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Why Iceland Chose Fish Over European Alliances
    • Guest opinion: Big Tech wants Wisconsin land for data centers. Voters are saying ‘Yeah, no.’
    • Did Muslim cashier demand Christian boy remove cross necklace? Here’s the truth
    • Trump threatens further action as US and Iran exchange fire in new flare-up | US-Israel war on Iran
    • Von der Leyen set to deliver major speech on Europe’s space policy – POLITICO
    • Serious questions over use of UK emergency alerts, its creators say
    • Burnham gets the early prison release changes he wanted – but at what cost?
    • George Santos Just Got Hit With Kalshi’s First-Ever Lifetime Ban
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 31
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ServiceNow Patches 3 Critical Code Injection Vulnerabilities

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 31, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    ServiceNow has announced patches for four vulnerabilities, including three critical code injection flaws in the ServiceNow AI platform, each with a maximum severity (CVSS score of 10/10).

    The first of the critical bugs, tracked as CVE-2026-18885, allows an attacker to execute arbitrary code in the ServiceNow platform under certain circumstances.

    An attacker could exploit the weakness to gain access to and potentially modify arbitrary data, ServiceNow notes in its advisory.

    The second critical defect, CVE-2026-18886, is described as an improper access control issue. It could allow an attacker to create or modify arbitrary data and elevate their privileges.

    Tracked as CVE-2026-74820, the third critical vulnerability is an SQL injection flaw that allows an attacker to execute arbitrary SQL statements against the underlying ServiceNow database.

    An attacker could exploit the bug to “gain access to, or modify, instance data beyond what was intended,” ServiceNow says.

    Advertisement. Scroll to continue reading.

    According to the company, none of the three vulnerabilities requires authentication or user interaction. All three can be exploited in low-complexity attacks.

    The fourth issue, tracked as CVE-2026-6876 (CVSS score of 8.7), is a high-severity sandbox escape weakness that could be exploited without authentication for code execution within the Now Platform.

    An attacker could exploit the security defect to gain “more access to the Now Platform than intended,” the company says.

    ServiceNow says it has rolled out patches for all four vulnerabilities across its hosted instances. The company also released hotfixes for self-hosted instances, encouraging customers to apply them as soon as possible.

    The hotfixes are available for ServiceNow’s Xanadu, Yokohama, Zurich, and Australia releases.

    According to iCOUNTER director of counter fraud operations Jason Brown, security teams should prioritize patching their ServiceNow instances, as attackers are quick to exploit newly discovered vulnerabilities. 

    “Everyone running ServiceNow on their own infrastructure now has to go find, schedule, and apply that patch themselves, and in a lot of organizations that process takes weeks, not days. During those weeks, an unauthenticated attacker with a working exploit for the GraphQL Composite Data API code injection bug or the SQL injection flaw has a real shot at systems that sit next to HR records, vendor onboarding, and finance approvals,” Brown said. 

    “I spent years chasing fraud operators who specifically target that lag between disclosure and patch adoption, because they know it’s where the easy access is. My advice to any security team running ServiceNow self-hosted right now is simple: don’t wait for your normal patch cycle, treat this one as urgent and confirm it’s applied this week,” he added. 

    Related: Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

    Related: CISA Warns of Exploited Gitea Vulnerability

    Related: Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

    Related: Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

    Code critical Injection Patches ServiceNow Vulnerabilities
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit

    ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

    ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

    Microsoft says Windows 11 KB5120998 update resets mouse settings

    Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

    China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Why Iceland Chose Fish Over European Alliances

    August 31, 2026

    Guest opinion: Big Tech wants Wisconsin land for data centers. Voters are saying ‘Yeah, no.’

    August 31, 2026

    Did Muslim cashier demand Christian boy remove cross necklace? Here’s the truth

    August 31, 2026

    Trump threatens further action as US and Iran exchange fire in new flare-up | US-Israel war on Iran

    August 31, 2026
    Latest Posts

    The future of AI hinges on openness and cooperation. China and Britain can gain much by working together | Zheng Zeguang

    July 30, 2026

    Drought declared for whole of Wales amid sustained high temperatures

    July 30, 2026

    This 4,000-year-old city defied the rules of history

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Why Iceland Chose Fish Over European Alliances

    August 31, 2026

    Guest opinion: Big Tech wants Wisconsin land for data centers. Voters are saying ‘Yeah, no.’

    August 31, 2026

    Did Muslim cashier demand Christian boy remove cross necklace? Here’s the truth

    August 31, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.