ServiceNow Patches Four AI Platform Flaws, Three Rated Maximum CVSS Severity

ServiceNow Patches Four AI Platform Flaws, Three Rated Maximum CVSS Severity

ServiceNow has disclosed and patched four security vulnerabilities in its AI Platform, three of which received the maximum possible CVSS severity score of 10.0. The fourth flaw was scored between 8.7 and 9.5 depending on scoring context. The issues are tracked as CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, and CVE-2026-6876.

What the Vulnerabilities Allow

According to ServiceNow's disclosure, the flaws could have allowed unauthenticated attackers to execute arbitrary code, escalate privileges, or perform SQL injection against affected instances. Security researchers have repeatedly flagged the low attack complexity associated with these vectors as a concern, particularly given how widely the platform is deployed across large enterprises.

Who Needs to Act: Hosted vs. Self-Hosted Customers

Hosted ServiceNow instances reportedly received automatic protections as part of the vendor's standard update process. Self-hosted deployments, however, require manual patch application through official ServiceNow knowledge base advisories. This distinction is critical for IT and security teams prioritizing remediation efforts, since self-hosted environments remain exposed until administrators act.

Exploitation Status: No Confirmed Attacks, But Caution Warranted

As of the most recent reporting on August 28, 2026, none of the four CVEs appear in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog. ServiceNow has stated that it has not observed evidence of exploitation affecting its hosted instances, and no public exploit code or technical write-up has surfaced. Still, the absence of confirmed exploitation today does not preclude future weaponization, especially once technical details become more widely available.

Context: A Related Flaw and a Correction

A previously reported, related vulnerability, CVE-2026-6875, was initially described as having in-the-wild exploitation. Researcher Defused later issued a correction, clarifying that the observed activity matched a public proof-of-concept rather than representing a novel attack. This episode serves as a useful reminder of the importance of verifying exploitation claims before they circulate widely.

Why Vendor-Assigned CVSS Scores Deserve Scrutiny

ServiceNow, acting as its own CVE Numbering Authority, self-assigned the severity ratings for these flaws. Independent enrichment through the National Institute of Standards and Technology's National Vulnerability Database does not currently apply, a result of recent policy changes affecting vendor-reported CVEs. Security observers suggest that readers and enterprise defenders should treat vendor-claimed severity as a starting point rather than an independently verified assessment, without implying any wrongdoing or misrepresentation on ServiceNow's part.

What This Means for Enterprise Security Teams

Security teams are generally advised to review and apply available patches promptly, particularly for self-hosted instances that do not benefit from automatic protections. Monitoring the CISA KEV catalog and official vendor advisories for updates on exploitation status is also commonly recommended. Even absent confirmed in-the-wild activity, maximum CVSS scores are widely treated by practitioners as urgent signals warranting timely attention rather than definitive proof of active compromise.

More Tech articles · CuencaLife home