SolutionsWorkshopsBlogNewsAboutLet's Talk
HomeNewsAI security and governance
Security

ServiceNow patches three max severity AI Platform flaws

Three CVSS 10.0 vulnerabilities in ServiceNow AI Platform are exploitable without authentication. Self-hosted customers must patch manually.

Automush
Published 30.08.2026
What this means for your business

If your organisation uses ServiceNow AI Platform on a self-hosted instance, install the patches today. CVSS 10.0 vulnerabilities exploitable without authentication allow an attacker to execute code, escalate privileges, and extract data directly from the database. If you are evaluating an enterprise AI platform, require vendors to document their security update process, response times for critical vulnerabilities, and commitment to automatic updates or immediate alerts.

ServiceNow published security patches on 28 August 2026 for three maximum severity 10.0 vulnerabilities in its AI Platform. All three are exploitable by unauthenticated attackers without user interaction. The platform is used by 85% of Fortune 500 companies.

What happened in detail

The vulnerabilities are CVE-2026-18885 (code injection), CVE-2026-18886 (privilege escalation), and CVE-2026-74820 (SQL injection). Each receives the highest possible CVSS rating, meaning they are remotely exploitable, require no authentication, and allow an attacker full control of the system.

ServiceNow updated cloud-hosted instances automatically, but customers with self-hosted instances must install the patches themselves. This is a critical gap: in many enterprise environments, security updates require internal approvals, compatibility testing, and scheduled maintenance windows.

Why it matters beyond the headline

Enterprise AI platforms hold customer data, regulatory data, and sensitive business information. An SQL injection vulnerability allows an attacker to extract the entire contents of the database. Privilege escalation allows an attacker to become a system administrator. Code injection allows arbitrary code execution on the server.

The fact that three maximum severity vulnerabilities were discovered in the same platform at the same time points to a structural problem in the testing process or architecture. This is not a single bug, it is a pattern.

For organisations in Israel subject to financial regulation or information security standards, such exposure is a reportable event. Even if the system was updated before exploitation, the exposure and response time must be documented.

What to do this week

If you use ServiceNow AI Platform on a self-hosted instance, install the patches immediately. If you cannot update within the next week, isolate the system from the public network or restrict access to internal network only.

If you are evaluating an enterprise AI platform, build a list of security questions for vendors: what is their average response time for critical vulnerabilities? Do they provide automatic updates or require manual installation? Do they have an internal vulnerability discovery process or rely on external researchers?

For companies building custom AI systems, this reinforces the need for multi-layered security architecture: network isolation, minimal permissions, and periodic penetration testing. A well-built system does not allow a single vulnerability to expose the entire database. Read more about AI agents for business and their unique requirements.

Sources

Frequently asked

How do I know if my ServiceNow instance is self-hosted or cloud?

If you connect to a URL ending in service-now.com, the instance is cloud-hosted and was updated automatically. If you connect to an internal server or custom address, the instance is self-hosted and you must install the patches manually.

What is the difference between a 10.0 severity vulnerability and a regular one?

A 10.0 rating means the vulnerability is remotely exploitable without authentication, requires no user interaction, and allows full control of the system. It is the highest possible rating and requires immediate patching.

Want to know what this means for you?

A short call, no commitment, and we will tell you whether it is relevant to your business or not.