Arctic Wolf Security Bulletin
Arctic Wolf Security Bulletin

ServiceNow AI Platform – Critical Max Severity Vulnerabilities

Learn about critical ServiceNow AI Platform vulnerabilities, including multiple CVSS 10.0 flaws that could allow unauthenticated remote code execution, SQL injection, and unauthorized data access.
Arctic Wolf Security Bulletin
6 min read

Threat Summary

On August 27, 2026, ServiceNow disclosed several critical vulnerabilities in its AI Platform: CVE-2026-18885 (code injection in GraphQL Composite Data API, CVSS 10.0), CVE-2026-18886 (improper access control enabling unauthorized data modification, CVSS 10.0), CVE-2026-74820 (SQL injection, CVSS 10.0), and a related sandbox escape flaw, CVE-2026-6876 (CVSS 8.7). These flaws allow unauthenticated adversaries to execute arbitrary code, run SQL commands, or escalate privileges and modify data, without requiring credentials or user interaction.

Affected are multiple ServiceNow AI Platform release families with specific unpatched versions including Xanadu, Yokohama, Zurich, and Australia. ServiceNow has deployed security updates to hosted instances, but self-hosted or partner-managed deployments require urgent manual patching. These vulnerabilities are especially dangerous given that successful attacks could compromise or destroy service workflows, leak sensitive company data, or result in significant regulatory exposure.

There is currently no public exploit code and no confirmed exploitation of the latest CVEs. At the time of writing, CISA and US-CERT have not yet issued advisories, but industry analysts and security researchers strongly recommend immediate remediation and hardening.

Recommendations

Immediate Actions:

  • Apply all relevant ServiceNow hotfixes and patches for Australia, Xanadu, Yokohama, and Zurich families as outlined below. Confirm remediation via platform version and patch status on all instances (self-hosted and partner-managed).
    • Xanadu: Patch 11 Hot Fix 7a or later
    • Yokohama: Patch 12 Hot Fix 3b, Patch 13 Hot Fix 4 or later
    • Zurich: Patch 7b Hot Fix 3, Patch 8 Hot Fix 5, Patch 9 Hot Fix 6, Patch 10 Hot Fix 2m, Patch 10 Hot Fix 3, Patch 11, Patch 12 or later
    • Australia: Patch 2 Hot Fix 3, Patch 3 Hot Fix 2, Patch 3m, Patch 4, Patch 5 or later
  • For cloud-hosted ServiceNow, verify official notification of patch deployment; for on-prem or managed, apply patches manually.
  • Immediately restrict internet/external access to ServiceNow AI Platform components (e.g., via firewall or WAF) until fully patched.

Long-Term and Preventive Measures:

  • Harden Security Center settings: address non-compliant controls, enforce strong access management, enable script sandboxing, and configure high security and compliance modes.
  • Restrict AI feature activation and usage by roles; enable AI Control Tower for centralized policy enforcement.
  • Adopt ServiceNow Vault, hardened MID servers, network segmentation, and domain separation for regulated environments.
  • Enforce least privilege, audit all attachment uploads, and deploy end-to-end TLS 1.2+.

Temporary Workarounds

If immediate patching is unfeasible:

  • Isolate affected ServiceNow AI Platform instances from public networks; only permit access via internal IPs or VPN.
  • Apply strict WAF rules or reverse proxy configurations to block suspicious or unauthenticated traffic to API, GraphQL, and image upload endpoints.
  • Disable unnecessary AI features and image upload functionalities where business allows.
  • Increase anomaly-based monitoring/alerting for: unusual API calls, image upload events, SQL queries, outbound process spawning, or privilege/escalation attempts.
  • Note: These are temporary measures. Full mitigation requires full patch deployment. Workarounds do not prevent all attack vectors, especially from insiders or already-compromised systems.

References

Share this post: