ServiceNow patches three CVSS 10.0 AI Platform flaws
ServiceNow's KB3152242 advisory fixes three maximum-severity flaws, a GraphQL code injection, an access-control bypass, and a SQL injection, plus an 8.7 sandbox escape. Hosted instances are patched; self-hosted deployments must act.

ServiceNow on August 27 published advisory KB3152242 patching three flaws that each carry the maximum CVSS score of 10.0, plus a fourth high-severity bug. Before you treat this as another drop-everything emergency: ServiceNow says it is "not currently aware of exploitation" of any of the four, and it has already applied the fix to its own hosted instances. The exposure that is actually yours to close is self-hosted and partner-hosted deployments, which must apply the update by hand.
Three tens, and they are not the same bug
The temptation is to file all three as "an RCE." They are not, and the distinction changes how you hunt for exposure. Per ServiceNow and the writeups from The Hacker News and Secure-ISS:
- CVE-2026-18885 is a code injection in the GraphQL Composite Data API. Under certain circumstances an unauthenticated attacker can execute arbitrary code and read or modify instance data.
- CVE-2026-18886 is an improper access control flaw in the system configuration image upload processor. An unauthenticated attacker can escalate privileges and create or modify instance data.
- CVE-2026-74820 is a SQL injection reached through a dynamic-schema ORDER BY clause. An unauthenticated attacker can run arbitrary SQL against the instance database.
All three share the same maximum-severity CVSS 4.0 vector, CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H: network-reachable, low complexity, no privileges and no user interaction, with high impact to confidentiality, integrity and availability on both the vulnerable component and downstream systems. "No privileges required" is the line that matters. These are pre-auth.
The fourth flaw the headlines drop
Most coverage stops at "three CVSS 10.0 flaws." The advisory carries a fourth: CVE-2026-6876, a sandbox escape on the Now Platform rated 8.7, which ServiceNow describes as allowing unauthenticated arbitrary code execution. It is a notch below the tens on paper, but it is still pre-auth code execution and it ships in the same patch set, so there is no reason to treat it as optional.
What to patch
Hosted customers are covered; ServiceNow rolled the update to its own instances. If you run self-hosted, the fix lives in specific release-family builds. Per the advisory as read by The Hacker News and Secure-ISS, the patched trains are Xanadu Patch 11 Hot Fix 7a or later; Yokohama Patch 12 Hot Fix 3b or Patch 13 Hot Fix 4 or later; Zurich across Patch 7b Hot Fix 3, Patch 8 Hot Fix 5, Patch 9 Hot Fix 6, Patch 10 Hot Fix 2m or 3, and Patch 11 or 12; and Australia Patch 2 Hot Fix 3, Patch 3 Hot Fix 2, Patch 3m, Patch 4, or Patch 5. ServiceNow's own line is blunt: it "encourages" self-hosted and hosted customers alike "to apply the relevant patches if they have not already done so."
The comfort in "no known exploitation" is thin. Three unauthenticated paths to code execution and database access in a system that holds a company's tickets, assets and CMDB are exactly the kind of target that gets reverse-engineered from a patch within days, the same pattern we saw with the PaperCut zero-day emergency patch and the run of NetScaler SQL flaws added to CISA's KEV and the Gitea path bug. If your ServiceNow is self-hosted, do not wait for a KEV listing to force the schedule: pull your current release train, match it against the builds above, and patch this week.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free