AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 29 Aug, 08:42

ServiceNow patches three maximum-severity security flaws in its AI Platform

ServiceNow released patches for three AI Platform vulnerabilities rated 10.0, the highest score on the CVSS scale, plus a fourth high-severity flaw. All three can be exploited by an unauthenticated attacker with no user interaction. ServiceNow says it has not observed exploitation so far. Per BleepingComputer / The Hacker News.

ServiceNow published a security advisory on August 27, 2026, patching four vulnerabilities in its AI Platform (formerly the Now Platform), the enterprise software that powers more than 100,000 AI apps across 85% of Fortune 500 companies. Three of the flaws, CVE-2026-18885, CVE-2026-18886 and CVE-2026-74820, are rated 10.0, the maximum score on the CVSS scale: they cover a code injection bug in the GraphQL Composite Data API, an access-control flaw in the system configuration image upload processor that allows privilege escalation, and a SQL injection bug reachable through a dynamic schema ORDER BY clause. All three can be exploited by an unauthenticated attacker in a low-complexity attack that requires no user interaction. A fourth flaw, CVE-2026-6876, a sandbox escape, scored 8.7 and requires low privileges to exploit. ServiceNow says it is not currently aware of malicious exploitation of any of the four flaws, and no public exploit code had surfaced as of August 28, 2026. The 10.0 ratings are ServiceNow's own: since April 15, 2026, NIST has enriched only vulnerabilities that appear in CISA's Known Exploited Vulnerabilities catalog, affect federal government software, or are designated critical under Executive Order 14028, and none of these four flaws were on that list as of August 28, 2026, leaving ServiceNow's own assessment as the only severity rating on record. Sources: BleepingComputer, The Hacker News.

#cyber
Published on