ServiceNow patches three maximum severity platform flaws
đź”’ ServiceNow has released patches for three maximum-severity vulnerabilities in its ServiceNow AI Platform that enable low-complexity code injection, SQL injection, and privilege escalation without user interaction. Cloud instances have been updated, and self-hosted customers are urged to patch immediately. The flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) could allow attackers to execute arbitrary code, alter or create instance data, and run arbitrary SQL against the database. ServiceNow also patched a high-severity sandbox escape (CVE-2026-6876); the vendor reports no known exploitation to date.