Affected Systems

ServiceNow AI Platform versions: Xanadu (before Patch 11 HF 7a), Yokohama (before Patch 12 HF 3b / Patch 13 HF 4), Zurich (before Patch 7b HF 3 through Patch 12 depending on branch), Australia (before Patch 2 HF 3 through Patch 5). Four CVEs: CVE-2026-18885 (code injection via GraphQL), CVE-2026-18886 (access control bypass in image upload), CVE-2026-74820 (SQL injection via ORDER BY), CVE-2026-6876 (sandbox escape, CVSS 8.7). Affects self-hosted and partner-hosted instances requiring manual patching.

Exploitation Status

No active exploitation observed as of August 28, 2026. No public PoC code available for the three CVSS 10.0 flaws. ServiceNow-hosted instances already patched. Related vulnerability CVE-2026-6875 (July 2026) saw suspected exploitation that turned out to be researcher PoC activity.

Business Impact

Critical risk for self-hosted and partner-hosted ServiceNow AI Platform deployments. All three maximum-severity flaws are remotely exploitable without authentication or user interaction, allowing arbitrary code execution, privilege escalation, database manipulation, and access to sensitive instance data. Attack complexity rated low. ServiceNow-hosted customers already protected; self-hosted organizations must patch immediately. No CISA KEV listing yet, but CVSS 10.0 rating reflects complete system compromise potential.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately identify all self-hosted and partner-hosted ServiceNow AI Platform instances in your environment and verify their patch levels against the advisory
  • Apply vendor patches per ServiceNow's August 27, 2026 advisory: Xanadu Patch 11 HF 7a or later, Yokohama Patch 12 HF 3b / Patch 13 HF 4 or later, Zurich Patch 10 HF 3 / Patch 12 or later (depending on branch), Australia Patch 5 or later
  • Monitor ServiceNow instance logs for anomalous GraphQL API requests, unauthorized image uploads to system configuration endpoints, unusual SQL query patterns in ORDER BY clauses, and sandbox escape attempts
  • If immediate patching is not feasible, implement network segmentation to restrict unauthenticated access to ServiceNow AI Platform instances and require VPN or IP allowlisting
  • Review ServiceNow instance access logs from the past 90 days for indicators of compromise, focusing on unauthenticated API calls and privilege escalation events