CVE-2026-18885

Published Aug 27, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-18885 is a code injection vulnerability found within the ServiceNow AI Platform. This flaw specifically affects the GraphQL Composite Data API, allowing an unauthenticated attacker to execute arbitrary code on the platform. Successful exploitation of this vulnerability could enable an attacker to gain access to, or modify, instance data beyond what is intended. ServiceNow has released security updates and hotfixes for affected versions across its Xanadu, Yokohama, Zurich, and Australia release families to remediate this issue.

Description
ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances.  We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Source
psirt@servicenow.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
10
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-94

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

2

  1. ServiceNow'da üç kritik (CVSS 10.0) güvenlik açığı! Bulunan açıklardan CVE-2026-18885 kod çalıştırmaya, CVE-2026-18886 yetki yükseltmeye, CVE-2026-74820 ise SQL enjeksiyonuyla veri okuma ve değiştirmeye izin veriyor. https://t.co/fE5KzEEpii https://t.co/lPOHizxF

    @Siber_Bulten

    30 Aug 2026

    807 Impressions

    0 Retweets

    0 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  2. August 2026 CVE Advisory Notification - Security - Now Support Portal What you need to know: On August 27, 2026, ServiceNow issued CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820 regarding the underlying logic that allowed for the reported security issues. If

    @VistemSolutions

    30 Aug 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ServiceNow patched three CVSS 10.0 vulnerabilities August 28. All three: unauthenticated code injection or SQL injection in the AI Platform. CVE-2026-18885, CVE-2026-18886, CVE-2026-74820. Every internet-facing instance vulnerable until patched. #Cybersecurity

    @McM1Alex

    29 Aug 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CYBERSÉCURITÉ — 3 FAILLES CRITIQUES CVSS 10.0 DANS SERVICENOW ServiceNow a publié le 27 août 2026 des correctifs pour plusieurs vulnérabilités majeures de sa plateforme AI, dont trois classées 10/10 : • CVE-2026-18885 : exécution de code arbitraire • CVE-2026

    @ActuX_off

    29 Aug 2026

    47 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Security Bulletin: Multiple Critical Vulnerabilities in ServiceNow AI Platform - Three critical ServiceNow AI Platform vulnerabilities (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) may enable code injection, privilege escalation, or SQL inj... https://t.co/HQsgwH5UTu

    @RedLegg

    28 Aug 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 ServiceNow just disclosed 3 CVSS 10.0 vulnerabilities that need immediate attention. No authentication. No user interaction. Low attack complexity. CVE-2026-18885 can enable arbitrary code execution. CVE-2026-18886 can enable privilege escalation. CVE-2026-74820 can enable

    @thecybersecguru

    28 Aug 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 💀 Three ServiceNow AI Platform flaws rated CVSS 10.0 CVE-2026-18885, CVE-2026-18886, CVE-2026-74820 — unauthenticated code & SQL injection in Xanadu/Yokohama releases. 🔗 https://t.co/ZlwhR6wbuo

    @CyberOSINTIO

    28 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 SERVICE NOW USERS: PATCH THIS NOW. 3 new CVSS 10.0 vulnerabilities could let unauthenticated attackers cross critical security boundaries: 🔴 CVE-2026-18885 — Code injection / arbitrary code execution 🔴 CVE-2026-18886 — Privilege escalation / data modification

    @thecybersecguru

    28 Aug 2026

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Warning: Multiple vulnerabilities in #ServiceNow. #CVE-2026-6876 #CVE-2026-18885 #CVE-2026-18886 #CVE-2026-74820 CVSS: 8.7 CVSS: 10 These vulnerabilities combined can lead to a full system compromise. Read our advisory: https://t.co/dbEQKPJO28 and #Patch #Patch #Patch

    @CCBalert

    28 Aug 2026

    302 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  10. 🚨🚨🚨 CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, CVE-2026-74820 August 2026 CVE Advisory Notification - Security ServiceNow Posture https://t.co/KsNPftCqPv

    @autumn_good_35

    28 Aug 2026

    314 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. ServiceNow disclosed four critical vulnerabilities in Now Platform and AI Platform, including unauthenticated code injection via GraphQL API and SQL injection flaws. CVE-2026-18885 allows remote code execution and data tampering without credentials. CVE-2026-18886 enables

    @WorldCyberNewsX

    28 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug. #ServiceNow #CodeInjection #SQLInjection #CVE #InfoSec https://t.co/hgTi9FD49L

    @Daily_CyberSec

    28 Aug 2026

    778 Impressions

    4 Retweets

    9 Likes

    7 Bookmarks

    0 Replies

    0 Quotes