Executive Summary
In August 2026, ServiceNow disclosed four critical security vulnerabilities in its AI Platform, including three rated 10.0 on the CVSS scale. The flaws include CVE-2026-18885 (GraphQL code injection), CVE-2026-18886 (improper access control), and CVE-2026-74820 (SQL injection), all exploitable by unauthenticated attackers to execute arbitrary code, escalate privileges, and access sensitive data. ServiceNow deployed patches to hosted instances but left self-hosted customers to apply fixes independently, creating potential exposure windows for organizations managing their own deployments.
This incident highlights the growing threat landscape surrounding AI platforms and enterprise software-as-a-service solutions. With the increasing adoption of AI-powered business applications and the recent trend of maximum-severity vulnerabilities in cloud platforms, organizations face elevated risks from sophisticated attacks targeting critical infrastructure components that handle sensitive corporate data.
Why This Matters Now
The disclosure of three simultaneous CVSS 10.0 vulnerabilities in a widely-used enterprise platform demonstrates the critical security challenges facing AI-powered cloud services, especially as organizations rapidly adopt these technologies without adequate security controls and patching processes.
Attack Path Analysis
Attackers exploit three CVSS 10.0 vulnerabilities in ServiceNow AI Platform to achieve unauthenticated code execution and database access. Following initial compromise through GraphQL injection or improper access controls, attackers escalate privileges via system configuration manipulation, move laterally through compromised ServiceNow instances, establish command and control channels, exfiltrate sensitive data through SQL injection attacks, and cause operational impact through data corruption or service disruption.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Unauthenticated attackers exploit CVE-2026-18885 GraphQL Composite Data API code injection or CVE-2026-18886 system configuration image upload processor to gain initial access to ServiceNow instances
Related CVEs
CVE-2026-18885
CVSS 10A code injection vulnerability in the GraphQL Composite Data API that could enable an unauthenticated user to execute arbitrary code and gain access to, or modify, instance data.
Affected Products:
ServiceNow ServiceNow AI Platform – Xanadu before Patch 11 Hot Fix 7a, Yokohama before Patch 12 Hot Fix 3b and before Patch 13 Hot Fix 4, Zurich before multiple patch versions, Australia before Patch 5
Exploit Status:
no public exploitCVE-2026-18886
CVSS 10An improper access control vulnerability in the system configuration image upload processor that could enable an unauthenticated user to create or modify instance data, resulting in privilege escalation.
Affected Products:
ServiceNow ServiceNow AI Platform – Xanadu before Patch 11 Hot Fix 7a, Yokohama before Patch 12 Hot Fix 3b and before Patch 13 Hot Fix 4, Zurich before multiple patch versions, Australia before Patch 5
Exploit Status:
no public exploitCVE-2026-74820
CVSS 10A SQL injection vulnerability reached through a dynamic schema ORDER BY clause that could enable an unauthenticated user to execute arbitrary SQL statements against the instance's underlying database.
Affected Products:
ServiceNow ServiceNow AI Platform – Xanadu before Patch 11 Hot Fix 7a, Yokohama before Patch 12 Hot Fix 3b and before Patch 13 Hot Fix 4, Zurich before multiple patch versions, Australia before Patch 5
Exploit Status:
no public exploitCVE-2026-6876
CVSS 8.7A sandbox escape in the Now Platform that could allow an unauthenticated user to execute arbitrary code within the Now Platform.
Affected Products:
ServiceNow ServiceNow AI Platform – Xanadu before Patch 11 Hot Fix 7a, Yokohama before Patch 12 Hot Fix 3b and before Patch 13 Hot Fix 4, Zurich before multiple patch versions, Australia before Patch 5
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter
Process Injection
Abuse Elevation Control Mechanism
Valid Accounts
Data from Local System
Data Destruction
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Vulnerability Management Program
Control ID: 6.2.1
NYDFS 23 NYCRR 500 – Application Security
Control ID: 500.08
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Application Workloads
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
ServiceNow platform vulnerabilities expose IT service management systems to unauthenticated remote code execution, SQL injection, and privilege escalation attacks.
Financial Services
Critical CVSS 10.0 flaws threaten financial institutions using ServiceNow for regulatory compliance, customer data management, and operational workflows.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance violations and patient data breaches through ServiceNow AI platform code injection vulnerabilities.
Government Administration
Government agencies using self-hosted ServiceNow instances remain vulnerable to unauthenticated attacks enabling arbitrary code execution and data modification.
Sources
- Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQLhttps://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.htmlVerified
- ServiceNow Security Advisory KB3152242https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3152242Verified
- CVE-2026-18885 Recordhttps://www.cve.org/CVERecord?id=CVE-2026-18885Verified
- Searchlight Cyber ServiceNow Researchhttps://www.slcyber.io/research/smashing-the-servicenow-sandbox-pre-authentication-rceVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely limit the attack scope by constraining lateral movement between ServiceNow instances and reducing data exfiltration paths through segmented network access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial vulnerability exploitation may still occur, but CNSF workload isolation would likely constrain the attacker's ability to immediately access adjacent cloud resources and services beyond the initially compromised ServiceNow instance.
Control: Zero Trust Segmentation
Mitigation: While privilege escalation within ServiceNow may still occur, Zero Trust segmentation would likely constrain the elevated privileges to the specific workload segment, reducing the attacker's ability to leverage those privileges across the broader cloud environment.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain lateral movement between ServiceNow instances and connected systems, significantly reducing the attacker's reachability across multiple organizational environments and limiting inter-instance communication paths.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely detect and constrain unauthorized command and control communications, reducing the attacker's ability to maintain persistent channels and limiting outbound communication flows to approved destinations and protocols.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely constrain data exfiltration by limiting outbound data flows and restricting unauthorized database access paths, reducing the volume and scope of sensitive data that could be extracted from the compromised ServiceNow environment.
While operational disruption within the compromised ServiceNow instance may still occur, the overall organizational impact would likely be reduced due to constrained lateral movement and limited blast radius from earlier CNSF enforcement stages.
Impact at a Glance
Affected Business Functions
- IT Service Management (ITSM)
- Customer Service Operations
- Workflow Automation
- Enterprise Data Management
Estimated downtime: 3 days
Estimated loss: N/A
Potential unauthorized access to ServiceNow instance data including customer records, internal workflows, configuration data, and underlying database contents. Organizations using ServiceNow for ITSM and customer service operations face risk of complete data compromise through unauthenticated access.
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline IPS with Suricata signatures to detect and block known exploit patterns targeting ServiceNow vulnerabilities before they reach application endpoints
- • Deploy zero trust segmentation with identity-based policies to limit blast radius if ServiceNow instances are compromised, preventing lateral movement to connected systems
- • Enable egress security and policy enforcement to detect and block unauthorized data exfiltration attempts from compromised ServiceNow instances
- • Establish multicloud visibility and control to monitor ServiceNow traffic patterns for anomalous interactions and repeated malformed requests indicative of exploitation attempts
- • Apply Cloud Native Security Fabric (CNSF) with real-time inspection capabilities to provide distributed policy enforcement and autonomous detection of advanced threats targeting cloud-native platforms like ServiceNow



