AI Weekly Malaysia

Back to items Summaries

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

ID
18985
Status
summarized
Published
28 Aug 2026, 7:20 PM
Fetched
28 Aug 2026, 7:29 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.0
Created
28 Aug 2026, 7:32 PM
Tags
Audience
developersdatabase_learners

What happened

ServiceNow patched four vulnerabilities on August 27, 2026, including three CVSS 10.0 flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) that allow unauthenticated attackers to execute arbitrary code and SQL. Hosted instances were automatically updated, but self-hosted customers must manually apply the patches.

Why it matters

If your organization self-hosts ServiceNow, you must immediately apply the August 27, 2026 security update to prevent unauthenticated attackers from executing arbitrary code and SQL via the GraphQL API and image upload processor. For most independent developers and founders not using ServiceNow, no action is required.

Discussion angle

How enterprise platforms like ServiceNow handle patching unauthenticated RCEs and the responsibility shift between hosted and self-hosted instances.

Top