Skip to content
Rush Commerce
Software & Dev3 min read

Three CVSS 10.0 ServiceNow flaws: the patch list

ServiceNow patched three unauthenticated CVSS 10.0 flaws in its AI Platform on August 27, plus a sandbox escape. Fixed versions for Xanadu through Australia.

ServiceNow published four CVEs on August 27, and three of them are straight CVSS 10.0 — unauthenticated, low complexity, no user interaction. If your IT tickets, HR requests, or internal approvals run through ServiceNow, the version you are on right now is the whole question. This is the second time this summer the ServiceNow AI Platform has needed an emergency patch.

What actually happened

Per The Hacker News and BleepingComputer, the four issues are:

  • CVE-2026-18885 (10.0) — code injection in the GraphQL Composite Data API. An unauthenticated user executes arbitrary code and reads or modifies instance data.
  • CVE-2026-18886 (10.0) — improper access control in the system configuration image upload processor. Unauthenticated create/modify of instance data, ending in privilege escalation.
  • CVE-2026-74820 (10.0) — SQL injection through a dynamic schema ORDER BY clause. Unauthenticated arbitrary SQL against the instance database.
  • CVE-2026-6876 (8.7) — sandbox escape in the Now Platform, requiring low privileges, ending in code execution.

Fixed versions, by release family: Xanadu Patch 11 Hot Fix 7a and later; Yokohama Patch 12 HF 3b or Patch 13 HF 4 and later; Zurich Patch 7b HF 3, 8 HF 5, 9 HF 6, or Patch 10 and later; Australia Patch 2 HF 3 or Patch 3 and later. ServiceNow has updated its hosted instances and says it is not aware of malicious exploitation of these specific flaws. Self-hosted customers apply their own patches.

Why an unauthenticated CVSS 10.0 matters for your business

"Not aware of exploitation" has a short shelf life here. In July, CVE-2026-6875 went from patch to active attack in days — and self-hosted customers got the fix three months after hosted ones did. The gap between disclosure and a working public exploit for an unauthenticated SQL injection is measured in hours by people who do this for a living.

Look at where these bugs live: a GraphQL data API, an image upload processor, an ORDER BY clause built from a dynamic schema. Those are the seams of a platform that lets customers extend it — configurable schemas, custom apps, uploaded assets. Every extension point is an input the vendor has to sanitize on your behalf, and ServiceNow runs more than 100,000 enterprise AI apps.

Two things to do today. Find your instance version and compare it to the list above — not "IT handles it," the actual patch string. Check whether the instance is internet-facing, because unauthenticated plus reachable is the entire risk model. If you run self-hosted, you own the clock; nobody patches it for you at 2am.

And if a workflow platform holds your identity data, ticket history, and half your internal automation, treat its advisory feed like your own release notes. That is not extra work. That is the cost of the platform.

Key takeaways

  • Three CVSS 10.0 flaws in the ServiceNow AI Platform, disclosed August 27: code injection, access control bypass, and SQL injection — all unauthenticated
  • A fourth, CVE-2026-6876 (8.7), is a sandbox escape to code execution with low privileges
  • Patch to Xanadu P11 HF7a+, Yokohama P12 HF3b / P13 HF4+, Zurich P7b HF3 / 8 HF5 / 9 HF6 / 10+, or Australia P2 HF3 / P3+
  • Hosted instances are updated. Self-hosted deployments own the patch and the timeline

How many vendor platforms sit between your customers and your data? Most teams can't list them, let alone their patch levels. We map the third-party surface of the systems we build on, keep the advisory feeds in one place, and tell you which ones are internet-facing before someone else finds out. See how we run it or book a stack review.

Sources: The Hacker News — Three CVSS 10.0 ServiceNow Flaws, BleepingComputer — ServiceNow warns of three max severity security vulnerabilities.

  • #servicenow
  • #cve
  • #rce
  • #sql-injection
  • #patching
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.