Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Russia kills 27 as drone hits ammo warehouse near homes in Ukraine – POLITICO

    August 29, 2026

    Tax promises, defence targets and Iran: Andy Burnham’s budget headaches | Budget

    August 29, 2026

    Fact-Checking Senate Races in Georgia, Alaska and Texas

    August 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Russia kills 27 as drone hits ammo warehouse near homes in Ukraine – POLITICO
    • Tax promises, defence targets and Iran: Andy Burnham’s budget headaches | Budget
    • Fact-Checking Senate Races in Georgia, Alaska and Texas
    • Friend-focused photo-sharing app Retro snags $21M
    • ServiceNow warns of three max severity security vulnerabilities
    • What Is Strategy (MSTR)? The Bitcoin Treasury Company
    • The Grid Has Eyes – Inside Climate News
    • The hill I will die on: The barbecue is fundamentally unenjoyable. Please, put a lid on it | Max Liu
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ServiceNow warns of three max severity security vulnerabilities

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 29, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks.

    The ServiceNow AI Platform (formerly known as the Now Platform) is an enterprise-grade Platform-as-a-Service (PaaS) that helps integrate AI into core enterprise workflows and powers more than 100,000 enterprise AI apps at 85% of all Fortune 500 companies.

    In a Thursday advisory, the company said it patched its cloud-based platform against the three critical security flaws (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820) and advised customers to secure their self-hosted instances.

    image

    The first is a code injection vulnerability that can allow attackers to execute arbitrary code, the second stems from a code injection weakness that enables them to escalate privileges, and the third allows threat actors to access or modify instance data through SQL injection attacks.

    All three security vulnerabilities can be exploited by unauthenticated threat actors in low-complexity attacks that don’t require user interaction.

    On Thursday, ServiceNow also addressed a high-severity sandbox escape security issue (CVE-2026-6876) affecting the same platform that could let attackers with basic privileges gain remote code execution on targeted systems.






    Release Version Updated
    Xanadu   Patch 11 Hot Fix 7a  
    Yokohama   Yokohama Patch 12 Hot Fix 3b

    Yokohama Patch 13 Hot Fix 4  
    Zurich   Zurich Patch 7b Hot Fix 3

    Zurich Patch 8 Hot Fix 5

    Zurich Patch 9 Hot Fix 6

    Zurich Patch 10 Hot Fix 2m (m-branch)

    Zurich Patch 10 Hot Fix 3 (standard)

    Zurich Patch 11

    Zurich Patch 12
    Australia   Australia Patch 2 Hot Fix 3

    Australia Patch 3 Hot Fix 2

    Australia Patch 3m

    Australia Patch 4

    Australia Patch 5

    “We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so,” the company said.

    While ServiceNow didn’t flag any of the vulnerabilities patched on Thursday as actively exploited, multiple security flaws in ServiceNow products have been targeted in attacks in recent years.

    Two years ago, threat actors chained three ServiceNow flaws (CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217) using publicly available exploits to breach private firms and government agencies worldwide in data theft attacks.

    More recently, in July, threat intelligence company Defused reported that attackers are now exploiting another critical vulnerability (CVE-2026-6875), a pre-auth sandbox escape in the ServiceNow AI Platform.

    ServiceNow has also privately disclosed a security incident last month in which security researchers or customer-led research used an unauthenticated access flaw via a vulnerable API endpoint to query data from customer instances.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Max Security ServiceNow severity Vulnerabilities warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    The hill I will die on: The barbecue is fundamentally unenjoyable. Please, put a lid on it | Max Liu

    Toy-making giant Hasbro disclose data breach affecting employees

    Key Reasons Why Identity Fabric Matters in 2026

    19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

    GiveWP WordPress donation plugin flaw lets hackers execute server commands

    The Vulnpocalypse Is Repricing the Bug Bounty Economy

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Russia kills 27 as drone hits ammo warehouse near homes in Ukraine – POLITICO

    August 29, 2026

    Tax promises, defence targets and Iran: Andy Burnham’s budget headaches | Budget

    August 29, 2026

    Fact-Checking Senate Races in Georgia, Alaska and Texas

    August 29, 2026

    Friend-focused photo-sharing app Retro snags $21M

    August 29, 2026
    Latest Posts

    NASA Awards 2026 Innovative Technology Concepts

    July 30, 2026

    Microsoft Quietly Adds New Windows App That Wants to Scan Your Face

    July 30, 2026

    US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Russia kills 27 as drone hits ammo warehouse near homes in Ukraine – POLITICO

    August 29, 2026

    Tax promises, defence targets and Iran: Andy Burnham’s budget headaches | Budget

    August 29, 2026

    Fact-Checking Senate Races in Georgia, Alaska and Texas

    August 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.