Affected Systems
ServiceNow AI Platform versions: Xanadu (before Patch 11 HF 7a), Yokohama (before Patch 12 HF 3b / Patch 13 HF 4), Zurich (before Patch 7b HF 3 through Patch 12 depending on branch), Australia (before Patch 2 HF 3 through Patch 5). Four CVEs: CVE-2026-18885 (code injection via GraphQL), CVE-2026-18886 (access control bypass in image upload), CVE-2026-74820 (SQL injection via ORDER BY), CVE-2026-6876 (sandbox escape, CVSS 8.7). Affects self-hosted and partner-hosted instances requiring manual patching.
Exploitation Status
No active exploitation observed as of August 28, 2026. No public PoC code available for the three CVSS 10.0 flaws. ServiceNow-hosted instances already patched. Related vulnerability CVE-2026-6875 (July 2026) saw suspected exploitation that turned out to be researcher PoC activity.
Business Impact
Critical risk for self-hosted and partner-hosted ServiceNow AI Platform deployments. All three maximum-severity flaws are remotely exploitable without authentication or user interaction, allowing arbitrary code execution, privilege escalation, database manipulation, and access to sensitive instance data. Attack complexity rated low. ServiceNow-hosted customers already protected; self-hosted organizations must patch immediately. No CISA KEV listing yet, but CVSS 10.0 rating reflects complete system compromise potential.
Urgency
🔴 Immediate
Recommended Actions
- Immediately identify all self-hosted and partner-hosted ServiceNow AI Platform instances in your environment and verify their patch levels against the advisory
- Apply vendor patches per ServiceNow's August 27, 2026 advisory: Xanadu Patch 11 HF 7a or later, Yokohama Patch 12 HF 3b / Patch 13 HF 4 or later, Zurich Patch 10 HF 3 / Patch 12 or later (depending on branch), Australia Patch 5 or later
- Monitor ServiceNow instance logs for anomalous GraphQL API requests, unauthorized image uploads to system configuration endpoints, unusual SQL query patterns in ORDER BY clauses, and sandbox escape attempts
- If immediate patching is not feasible, implement network segmentation to restrict unauthenticated access to ServiceNow AI Platform instances and require VPN or IP allowlisting
- Review ServiceNow instance access logs from the past 90 days for indicators of compromise, focusing on unauthenticated API calls and privilege escalation events
