Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical ThreatIntel

ServiceNow Patches Three Critical AI Platform Vulnerabilities (Code Injection, SQL Injection, Privilege Escalation)

ServiceNow released patches for three maximum‑severity AI Platform flaws that allow unauthenticated code injection, privilege escalation, and SQL injection. The issue highlights the need for continuous SOC 2 control mapping and real‑time patch‑evidence collection.

LiveThreat™ Intelligence · 📅 August 28, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

ServiceNow Patches Three Critical AI Platform Vulnerabilities (Code Injection, SQL Injection, Privilege Escalation)

What Happened — ServiceNow disclosed three maximum‑severity vulnerabilities (CVE‑2026‑18885, CVE‑2026‑18886, CVE‑2026‑74820) in its AI Platform that enable unauthenticated code injection, privilege escalation, and SQL injection. A fourth high‑severity sandbox‑escape flaw (CVE‑2026‑6876) was also patched. All flaws can be exploited with low‑complexity attacks that require no user interaction.

Why It Matters for Compliance & Audit Readiness

  • These vulnerabilities map directly to SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations) – controls that require documented evidence of timely patching and configuration verification.
  • Continuous‑compliance programs must capture patch‑deployment evidence in real time to demonstrate due diligence during an audit.
  • Verisq’s Control Mapping capability can automatically correlate each patched CVE to the relevant SOC 2 control, generating audit‑ready evidence without manual effort.

Who Is Affected — Enterprises that run ServiceNow’s AI Platform (Now Platform) across any sector—technology SaaS providers, financial services, healthcare, and other Fortune 500 organizations.

Recommended Actions

  • Verify your instance version and apply the latest hot‑fixes (Xanadu 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b, etc.) immediately.
  • Update your SOC 2 control inventory to reflect the new patches and record the change in your configuration‑management system.
  • Use automated control‑mapping tools to link each CVE remediation to the corresponding SOC 2 control for audit evidence.

Source: BleepingComputer

Technical Notes —

  • CVE‑2026‑18885: Unauthenticated code injection → remote code execution.
  • CVE‑2026‑18886: Unauthenticated privilege‑escalation code injection.
  • CVE‑2026‑74820: Unauthenticated SQL injection allowing data read/modify.
  • CVE‑2026‑6876: Sandbox escape enabling remote code execution for low‑privilege users.

All are exploitable without user interaction; CVSS scores are 9.8‑10.0 (Critical).

📰 Original Source
https://www.bleepingcomputer.com/news/security/servicenow-warns-of-three-max-severity-security-vulnerabilities/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →