CVE-2026-18886 – ServiceNow AI Platform and Now Platform

CVSS 10 CRITICAL Critical - Same Day Deployment

“Three maximum-severity flaws can expose ServiceNow instances to unauthenticated code execution, privilege escalation, and database compromise.”

ServiceNow fixes three Critical vulnerabilities in the ServiceNow AI Platform. CVE-2026-18885 can allow an unauthenticated attacker to execute arbitrary code and access or modify instance data. CVE-2026-18886 can allow unauthenticated creation or modification of instance data resulting in privilege escalation. CVE-2026-74820 can allow an unauthenticated attacker to execute arbitrary SQL statements against the underlying database. Each has a CVSS score of 10.0, Critical severity.

CVE-2026-6876 affects the Now Platform and can allow an unauthenticated attacker to escape a sandbox and execute arbitrary code within the platform. The CVSS score is 8.7, which is High severity. ServiceNow deployed security updates to hosted instances and provided updates for partners and self-hosted customers.

Key Details

CWE Classification
CWE-284
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.