Three vulnerabilities ServiceNow assigned the maximum CVSS score of 10.0 — CVE-2026-18885, CVE-2026-18886 and CVE-2026-74820 — were disclosed in an August 27, 2026 advisory and, in certain circumstances, can be reached by an unauthenticated attacker to execute arbitrary code or SQL against a Now Platform instance.
The flaws and their technical reach
ServiceNow listed four separate issues in its advisory. Three carry a 10.0 CVSS rating and are described as follows:
- CVE-2026-18885 (CVSS 10.0) — a code injection vulnerability in the GraphQL Composite Data API that could enable an unauthenticated user to execute arbitrary code and gain access to, or modify, instance data.
- CVE-2026-18886 (CVSS 10.0) — an improper access control vulnerability in the system configuration image upload processor that could enable an unauthenticated user to create or modify instance data, resulting in privilege escalation.
- CVE-2026-74820 (CVSS 10.0) — a SQL injection vulnerability reached through a dynamic schema ORDER BY clause that could enable an unauthenticated user to execute arbitrary SQL statements against the instance's underlying database.
The three maximum-severity flaws share an identical CVSS vector as recorded by ServiceNow: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H — a network-reachable attack of low complexity requiring no privileges or user interaction, and carrying high impact to confidentiality, integrity and availability in both the vulnerable component and connected systems.
The advisory also listed CVE-2026-6876 (CVSS 8.7), described as a sandbox escape in the Now Platform that could allow an unauthenticated user to execute arbitrary code. ServiceNow assigned that flaw a CVSS vector that specifies PR:L (low privileges required) and records no impact to systems beyond the vulnerable component.
ServiceNow's response and patch distribution
ServiceNow said it has deployed a security update to its hosted instances and provided updates to partners and self-hosted customers. The company noted that organizations operating self-hosted instances must apply the fixes themselves. In a statement to The Hacker News, a ServiceNow spokesperson said, "ServiceNow is aware of a cybersecurity company's recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as CVE-2026-6875." The spokesperson added, "Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts."
The spokesperson also told The Hacker News, "We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so. In addition, we will continue to work directly with customers who need assistance in applying the patches."

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadPrior related activity: CVE-2026-6875 and public claims
The August advisory follows an earlier pre-authentication sandbox escape identified as CVE-2026-6875. Searchlight Cyber reported CVE-2026-6875 to ServiceNow on April 1, 2026; ServiceNow published an advisory for it on July 13. Shortly after that July advisory, threat intelligence firm Defused said it was observing in-the-wild exploitation of CVE-2026-6875, then later issued a correction stating the captured payload matched Searchlight Cyber's published proof-of-concept exploit.
The Hacker News reported ServiceNow's statement that, based on investigation to date, the company had not observed evidence that that activity was related to ServiceNow-hosted instances.
Affected releases, product-status nuances, and CVE handling
ServiceNow listed specific product branches and the versions it considers affected in the August advisory:
- Xanadu — any version before Patch 11 Hot Fix 7a
- Yokohama — any version before Patch 12 Hot Fix 3b, and any version before Patch 13 Hot Fix 4
- Zurich — any version before Patch 7b Hot Fix 3, Patch 8 Hot Fix 5, Patch 9 Hot Fix 6, Patch 10 Hot Fix 2m (m-branch), Patch 10 Hot Fix 3 (standard), Patch 11, or Patch 12
- Australia — any version before Patch 2 Hot Fix 3, Patch 3 Hot Fix 2, Patch 3m, Patch 4, or Patch 5
One record (CVE-2026-18886) marks "Any version before Australia Patch 5" with a status of unknown, while the other three list the same Australia release as affected. ServiceNow set a default product status of unaffected in all four records, meaning releases not named on the list fall outside the affected set.
ServiceNow is the CVE Numbering Authority for its products and assigned the 10.0 ratings itself. The company noted that since April 15, 2026, NIST has enriched only vulnerabilities that appear in CISA's Known Exploited Vulnerabilities catalog, affect federal government software, or are designated critical under Executive Order 14028. As of August 28, 2026, none of the four flaws appeared in CISA's catalog, leaving ServiceNow's ratings as the only severity assessment on record.
How self-hosted customers and security teams are positioned
Self-hosted ServiceNow customers are the obvious operational locus for follow-up: ServiceNow deployed updates to hosted instances and provided patches to partners and self-hosted customers, leaving on-premise operators responsible for applying those fixes. Security teams and technologists will also note ServiceNow's characterization that, for these four records, the company is "not currently aware of exploitation."
Researchers and incident responders working with captured exploit samples will observe that The Hacker News found no public exploit code for the three maximum-severity flaws as of August 28, 2026, and that Searchlight Cyber had published no technical write-up for the August disclosures at the time of reporting. Adam Kues of Searchlight Cyber wrote in July that ServiceNow was "enhancing instance security by severely restricting the type of code that can run in sandbox contexts."
ServiceNow's August 27 advisory places three high-impact, pre-authentication vulnerabilities on the record, with patches deployed to ServiceNow-hosted instances and made available to partners and self-hosted customers. As of August 28, 2026, ServiceNow said it had no evidence these new issues had been exploited in hosted instances, and no public exploit code for the three 10.0-rated flaws had been found.




