ServiceNow issued emergency patches on August 27 for three vulnerabilities rated 10.0 — the maximum score.
CVE-2026-18885: unauthenticated code injection through the GraphQL API.
CVE-2026-18886: privilege escalation via image upload.
CVE-2026-74820: SQL injection against the underlying database.
All three require zero authentication. No user interaction. Low complexity. An attacker needs only network access.
ServiceNow hosts its own cloud instances. But self-hosted customers must patch manually.
And the blast radius is not the platform. It is every credential, token, API, and workflow connected to it.
ServiceNow is the connective tissue of enterprise IT — ITSM, HR, customer workflows, approvals, integrations. Compromising it is not a single-app breach. It is a pivot point into your entire stack.
CSO Online quoted SANS CISO Ensar Seker: "Code injection can turn a trusted enterprise application into an attacker-controlled execution environment."
Beauceron Security's David Shipley: "You can take it to the bank that these are getting worked now."
Audit your ServiceNow instances today.
Check your patch level against the August 27 advisory. Inventory every API, integration, and privileged service account connected to the platform. Review telemetry for anomalous GraphQL requests and upload activity.
If you are running self-hosted ServiceNow and have not patched since July 13, you are already behind the threat curve.
Verify. Patch. Segment.
ServiceNow just dropped 3 CVSS 10.0 patches. Your AI workflow backbone is exposed.
AI-Assisted Content — Produced with AI assistance and human editorial review.
Learn more
0 Comments