Four flaws hand just been disclosed in ServiceNow’s AI Platform, three of them scored a maximum CVSS 10.0: a code injection bug in the GraphQL Composite Data API (CVE-2026-18885), a privilege escalation flaw in the system configuration image upload processor (CVE-2026-18886), and a SQL injection through a dynamic schema ORDER BY clause (CVE-2026-74820), plus a lower-severity sandbox escape in the Now Platform (CVE-2026-6876, CVSS 8.7). ServiceNow patched its own hosted instances on August 27, but self-hosted customers must apply the fix themselves, leaving the responsibility for closing three maximum-severity holes with the customer rather than the vendor.
Jason Brown, Director of Counter Fraud Operations, iCOUNTER had this to say:
“Three maximum severity bugs in one disclosure is a lot, but the detail I’d focus on is the split between hosted and self hosted customers. ServiceNow’s hosted instances were already updated as part of the August 27 advisory. Everyone running ServiceNow on their own infrastructure now has to go find, schedule, and apply that patch themselves, and in a lot of organizations that process takes weeks, not days. During those weeks, an unauthenticated attacker with a working exploit for the GraphQL Composite Data API code injection bug or the SQL injection flaw has a real shot at systems that sit next to HR records, vendor onboarding, and finance approvals. I spent years chasing fraud operators who specifically target that lag between disclosure and patch adoption, because they know it’s where the easy access is. My advice to any security team running ServiceNow self hosted right now is simple: don’t wait for your normal patch cycle, treat this one as urgent and confirm it’s applied this week.”
Needless to say, if you use ServiceNow, it’s time to patch all the things. And maybe at the same time take a look at how ServiceNow is used in your organization.
Related
This entry was posted on August 29, 2026 at 9:13 am and is filed under Commentary with tags ServiceNow. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
ServiceNow’s CVSS 10.0 trio shows how one platform patch cycle becomes everyone’s third-party risk problem
Four flaws hand just been disclosed in ServiceNow’s AI Platform, three of them scored a maximum CVSS 10.0: a code injection bug in the GraphQL Composite Data API (CVE-2026-18885), a privilege escalation flaw in the system configuration image upload processor (CVE-2026-18886), and a SQL injection through a dynamic schema ORDER BY clause (CVE-2026-74820), plus a lower-severity sandbox escape in the Now Platform (CVE-2026-6876, CVSS 8.7). ServiceNow patched its own hosted instances on August 27, but self-hosted customers must apply the fix themselves, leaving the responsibility for closing three maximum-severity holes with the customer rather than the vendor.
Jason Brown, Director of Counter Fraud Operations, iCOUNTER had this to say:
“Three maximum severity bugs in one disclosure is a lot, but the detail I’d focus on is the split between hosted and self hosted customers. ServiceNow’s hosted instances were already updated as part of the August 27 advisory. Everyone running ServiceNow on their own infrastructure now has to go find, schedule, and apply that patch themselves, and in a lot of organizations that process takes weeks, not days. During those weeks, an unauthenticated attacker with a working exploit for the GraphQL Composite Data API code injection bug or the SQL injection flaw has a real shot at systems that sit next to HR records, vendor onboarding, and finance approvals. I spent years chasing fraud operators who specifically target that lag between disclosure and patch adoption, because they know it’s where the easy access is. My advice to any security team running ServiceNow self hosted right now is simple: don’t wait for your normal patch cycle, treat this one as urgent and confirm it’s applied this week.”
Needless to say, if you use ServiceNow, it’s time to patch all the things. And maybe at the same time take a look at how ServiceNow is used in your organization.
Share this:
Like this:
Related
This entry was posted on August 29, 2026 at 9:13 am and is filed under Commentary with tags ServiceNow. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.