Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
- ID
- 18985
- Status
- summarized
- Published
- 28 Aug 2026, 7:20 PM
- Fetched
- 28 Aug 2026, 7:29 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.0
- Created
- 28 Aug 2026, 7:32 PM
- Tags
- Audience
- developersdatabase_learners
What happened
ServiceNow patched four vulnerabilities on August 27, 2026, including three CVSS 10.0 flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) that allow unauthenticated attackers to execute arbitrary code and SQL. Hosted instances were automatically updated, but self-hosted customers must manually apply the patches.
Why it matters
If your organization self-hosts ServiceNow, you must immediately apply the August 27, 2026 security update to prevent unauthenticated attackers from executing arbitrary code and SQL via the GraphQL API and image upload processor. For most independent developers and founders not using ServiceNow, no action is required.
Discussion angle
How enterprise platforms like ServiceNow handle patching unauthenticated RCEs and the responsibility shift between hosted and self-hosted instances.