ServiceNow Patches Three Critical AI Platform Vulnerabilities (Code Injection, SQL Injection, Privilege Escalation)
What Happened — ServiceNow disclosed three maximum‑severity vulnerabilities (CVE‑2026‑18885, CVE‑2026‑18886, CVE‑2026‑74820) in its AI Platform that enable unauthenticated code injection, privilege escalation, and SQL injection. A fourth high‑severity sandbox‑escape flaw (CVE‑2026‑6876) was also patched. All flaws can be exploited with low‑complexity attacks that require no user interaction.
Why It Matters for Compliance & Audit Readiness
- These vulnerabilities map directly to SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations) – controls that require documented evidence of timely patching and configuration verification.
- Continuous‑compliance programs must capture patch‑deployment evidence in real time to demonstrate due diligence during an audit.
- Verisq’s Control Mapping capability can automatically correlate each patched CVE to the relevant SOC 2 control, generating audit‑ready evidence without manual effort.
Who Is Affected — Enterprises that run ServiceNow’s AI Platform (Now Platform) across any sector—technology SaaS providers, financial services, healthcare, and other Fortune 500 organizations.
Recommended Actions
- Verify your instance version and apply the latest hot‑fixes (Xanadu 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b, etc.) immediately.
- Update your SOC 2 control inventory to reflect the new patches and record the change in your configuration‑management system.
- Use automated control‑mapping tools to link each CVE remediation to the corresponding SOC 2 control for audit evidence.
Source: BleepingComputer
Technical Notes —
- CVE‑2026‑18885: Unauthenticated code injection → remote code execution.
- CVE‑2026‑18886: Unauthenticated privilege‑escalation code injection.
- CVE‑2026‑74820: Unauthenticated SQL injection allowing data read/modify.
- CVE‑2026‑6876: Sandbox escape enabling remote code execution for low‑privilege users.
All are exploitable without user interaction; CVSS scores are 9.8‑10.0 (Critical).