SERVICENOW has released patches for four vulnerabilities, including three critical code injection flaws (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820), each rated with a CVSS score of 10/10. These vulnerabilities could allow attackers to execute arbitrary code and modify sensitive data without requiring authentication. A fourth vulnerability (CVE-2026-6876) has a CVSS score of 8.7 and allows for potential code execution within the Now Platform.
ServiceNow advises immediate patching due to the risk of exploitation, especially for self-hosted customers. Jason Brown from iCOUNTER stressed the urgency of applying patches, citing the rapid exploitation of such vulnerabilities by attackers.