Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    ServiceNow warns of three max severity security vulnerabilities

    August 29, 2026

    Over 8,300 Gitea servers vulnerable to code execution attacks

    August 29, 2026

    Brave browser adds email aliases to help users evade tracking

    August 29, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»ServiceNow warns of three max severity security vulnerabilities
    News

    ServiceNow warns of three max severity security vulnerabilities

    adminBy adminAugust 29, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    ServiceNow

    ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks.

    The ServiceNow AI Platform (formerly known as the Now Platform) is an enterprise-grade Platform-as-a-Service (PaaS) that helps integrate AI into core enterprise workflows and powers more than 100,000 enterprise AI apps at 85% of all Fortune 500 companies.

    In a Thursday advisory, the company said it patched its cloud-based platform against the three critical security flaws (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820) and advised customers to secure their self-hosted instances.

    image

    The first is a code injection vulnerability that can allow attackers to execute arbitrary code, the second stems from a code injection weakness that enables them to escalate privileges, and the third allows threat actors to access or modify instance data through SQL injection attacks.

    All three security vulnerabilities can be exploited by unauthenticated threat actors in low-complexity attacks that don’t require user interaction.

    On Thursday, ServiceNow also addressed a high-severity sandbox escape security issue (CVE-2026-6876) affecting the same platform that could let attackers with basic privileges gain remote code execution on targeted systems.






    Release Version Updated
    Xanadu   Patch 11 Hot Fix 7a  
    Yokohama   Yokohama Patch 12 Hot Fix 3b

    Yokohama Patch 13 Hot Fix 4  
    Zurich   Zurich Patch 7b Hot Fix 3

    Zurich Patch 8 Hot Fix 5

    Zurich Patch 9 Hot Fix 6

    Zurich Patch 10 Hot Fix 2m (m-branch)

    Zurich Patch 10 Hot Fix 3 (standard)

    Zurich Patch 11

    Zurich Patch 12
    Australia   Australia Patch 2 Hot Fix 3

    Australia Patch 3 Hot Fix 2

    Australia Patch 3m

    Australia Patch 4

    Australia Patch 5

    “We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so,” the company said.

    While ServiceNow didn’t flag any of the vulnerabilities patched on Thursday as actively exploited, multiple security flaws in ServiceNow products have been targeted in attacks in recent years.

    Two years ago, threat actors chained three ServiceNow flaws (CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217) using publicly available exploits to breach private firms and government agencies worldwide in data theft attacks.

    More recently, in July, threat intelligence company Defused reported that attackers are now exploiting another critical vulnerability (CVE-2026-6875), a pre-auth sandbox escape in the ServiceNow AI Platform.

    ServiceNow has also privately disclosed a security incident last month in which security researchers or customer-led research used an unauthenticated access flaw via a vulnerable API endpoint to query data from customer instances.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleOver 8,300 Gitea servers vulnerable to code execution attacks
    admin
    • Website

    Related Posts

    News

    Over 8,300 Gitea servers vulnerable to code execution attacks

    August 29, 2026
    News

    Brave browser adds email aliases to help users evade tracking

    August 29, 2026
    News

    Letters to the Standing Committee on Public Safety and National Security and Standing Committee on National Security, Defence and Veteran Affairs on NSIRA’s observations and recommendations regarding potential opportunities to further strengthen its legislative framework and governance structure

    August 29, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    ServiceNow warns of three max severity security vulnerabilities

    August 29, 2026

    Over 8,300 Gitea servers vulnerable to code execution attacks

    August 29, 2026

    Brave browser adds email aliases to help users evade tracking

    August 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.