logo

ServiceNow warns of three max severity security vulnerabilities

ID: e30da14d-37e4-5aba-9022-ddc1bc60e284

STIX ID: report--e30da14d-37e4-5aba-9022-ddc1bc60e284

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

Author: Sergiu Gatlan

...
...

ServiceNow issued patches for three critical AI Platform vulnerabilities (unauthenticated code injection, privilege escalation, and SQL injection: CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) and a high-severity sandbox escape (CVE-2026-6876); the issues are low-complexity and can be exploited without authentication, so customers are urged to apply updates promptly despite no confirmed active exploitation of these specific flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.