Skip to main content
Back to News
ServiceNow disclosed four vulnerabilities in its AI Platform on August 27, three of them rated a maximum 10.0 on the CVSS scale.
Technology
2 min read
US

ServiceNow disclosed four vulnerabilities in its AI Platform on August 27, three of them rated a maximum 10.0 on the CVSS scale.

The AMW Read

A known enterprise-agent platform player discloses maximum-severity CVEs in the exact AI Platform it markets for autonomous agents, the second such disclosure in two months, raising trust/governance stakes for the segment without resolving an open debate.
NoveltySignificance
AI Agents · Player Map

ServiceNow disclosed four vulnerabilities in its AI Platform on August 27, three of them rated a maximum 10.0 on the CVSS scale.

On August 27, ServiceNow disclosed four vulnerabilities in its Now Platform, affecting the Xanadu, Yokohama, Zurich, and Australia releases. CVE-2026-18885 is a code-injection flaw in the GraphQL Composite Data API letting an unauthenticated attacker execute arbitrary code and read or rewrite instance data. CVE-2026-18886 is an improper access-control bug in the system configuration image upload processor that lets an outsider escalate privileges without credentials. CVE-2026-74820 is a SQL injection flaw reachable through a dynamic schema ORDER BY clause, exposing the underlying database. A fourth flaw, CVE-2026-6876, is a sandbox escape rated 8.7. ServiceNow said the bugs surfaced through its internal research and responsible-disclosure program, has patched hosted instances, and reports no evidence of active exploitation; self-hosted customers must apply fixes themselves.

The vulnerable component is the same AI Platform ServiceNow markets as the execution layer for autonomous agents triaging IT tickets, running HR onboarding, and executing workflow approvals inside enterprises. Three unauthenticated, zero-privilege, maximum-severity bugs in that layer sit awkwardly next to the governance claims vendors are making to get enterprises comfortable handing agents more autonomy. It is also the second serious AI Platform disclosure in two months, after a July pre-authentication sandbox escape, CVE-2026-6875, in the same platform family.

For enterprises running self-hosted ServiceNow instances, this is exposure, not housekeeping: unauthenticated code execution in a system wired into ticketing, HR, and workflow credentials opens a direct path to lateral movement across connected systems. Security and procurement teams evaluating agent platforms should treat vulnerability-disclosure cadence and patch latency as a due-diligence line item alongside agent-capability claims, especially where the agent's blast radius includes credentials and APIs the platform can reach.

#ServiceNow #AIAgents #EnterpriseSecurity #Cybersecurity #AIPlatform #VulnerabilityDisclosure

#ServiceNow#AI agent security#CVSS 10.0#vulnerability disclosure#Now Platform#enterprise AI agents

How This Connects

Based on AI Agents · Player Map

  1. 8h agoServiceNow disclosed four vulnerabilities in its AI Platform on August 27, three of them rated a maximum 10.0 on the CVSS scale. · THIS ARTICLE
  2. 1w agoNvidia Research Puts Agent Harness Design Ahead of Base-Model QualityNvidia
  3. 2w agoAnthropic's Frontier Red Team published a study on August 13, 2026, revealing that when three instan...Anthropic
  4. 2w agoTencent is set to become the largest shareholder of AI developer Manus, as Meta unwinds its acquisit...Manus
  5. 2w agoMeta will unwind its $2 billion acquisition of Manus AI after Beijing ordered the deal to be reverse...Manus
  6. 3w agoHugging Face hack marks start of agentic AI cyber era, execs warn firms 'don't even know it'Hugging Face

Related News

More news from ServiceNow

Stay updated with the latest news and announcements from ServiceNow.

View all ServiceNow news

Discover AI Startups

Explore 5,000+ AI companies with VC-grade analysis, funding data, and investment insights.

Explore Dashboard