ServiceNow Patches Three CVSS 10 AI Flaws
ServiceNow disclosed patches for four AI Platform vulnerabilities, including three CVSS 4.0 vulnerabilities rated 10.0. Hosted instances were updated, but self-hosted and partner-managed customers must apply fixes. Advisory: https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3152242
This is a serious platform-security failure with an AI-era blast radius, though not evidence that ServiceNow’s models themselves are unsafe. Because AI agents operate over core enterprise data and workflows, flaws in the underlying plumbing can turn into cross-department compromise. Source: The Hacker News — https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
- –CVE-2026-18885 affects the GraphQL Composite Data API, potentially allowing unauthenticated arbitrary code execution and data tampering.
- –CVE-2026-18886 enables unauthorized data changes and privilege escalation through an image-upload processor.
- –CVE-2026-74820 exposes the underlying database to arbitrary SQL statements through a dynamic schema clause.
- –ServiceNow reports no known exploitation of these four flaws, but operators should urgently verify patched release levels and audit exposed instances.
DISCOVERED
1h ago
2026-08-31
PUBLISHED
1h ago
2026-08-31
RELEVANCE
AUTHOR
XQOPTRX