Security2 distinct publishers3 min readPublished
ServiceNow fixed its own hosted fleet on August 27 and handed the same update to partners and self-hosted customers, whose unauthenticated GraphQL and SQL exposure stays open until someone on staff installs it.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
CVE-2026-18886 is the one both write-ups treat as an afterthought. ServiceNow describes it as improper access control in the system configuration image upload processor, letting an unauthenticated user create or modify instance data and escalate privileges [4]. The three maximum-severity records share one vector string, and the tail of it matters more than the 10.0: SC:H/SI:H/SA:H, meaning high impact to the systems connected to the vulnerable component, not only the component [6]. That is scoring language for blast radius, and this platform integrates AI into core enterprise workflows and runs more than 100,000 enterprise AI apps at 85 percent of the Fortune 500 [20].
The scores are ServiceNow's own. It is the CVE Numbering Authority for its products [15], and since April 15, 2026 NIST has enriched only vulnerabilities in CISA's Known Exploited Vulnerabilities catalog, those affecting federal government software, or those designated critical under Executive Order 14028 [16]. None of the four was in the catalog as of August 28, so the vendor's rating is the only assessment on record [17]. Read it against July: ServiceNow scored CVE-2026-6875 at 9.5 with every metric identical to the new three except attack complexity, which it set to high [13]. The half point is attack complexity and nothing else [14]. AC:L on the new three is the vendor saying no special conditions are required.
July is why that metric carries weight. Searchlight Cyber reported CVE-2026-6875 on April 1, 2026, and ServiceNow published on July 13, 103 days later [10][23]. Days after that advisory, Defused said it was observing in-the-wild exploitation, then corrected itself: the captured payload matched Searchlight's published proof of concept [11]. ServiceNow said it had seen no evidence the activity involved instances it hosts [12]. What is public, then, is a payload derived from a public PoC landing on reachable instances. Malicious operator activity stays unconfirmed.
Forty-five days separate the two advisories [24]. The pattern around this platform is consistent. In 2024, attackers chained CVE-2024-4879, CVE-2024-5178 and CVE-2024-5217 with publicly available exploits to breach private firms and government agencies worldwide [21]. Last month, according to BleepingComputer, ServiceNow privately disclosed an incident in which researchers or customer-led research used an unauthenticated access flaw in a vulnerable API endpoint to query data from customer instances [22]. Unauthenticated reach into instance data is the recurring shape here.
One detail for anyone on the Australia release train. The record for CVE-2026-18886 marks any version before Australia Patch 5 with a status of unknown, while the records for the other three mark that same version affected, and all four default to unaffected for releases the list does not name [19]. On that branch, the advisory does not tell you whether the image upload flaw reaches you.
Ranked by verification strength, evidence, and original report placement.
ServiceNow published an advisory on August 27, 2026 covering four security flaws in the ServiceNow AI Platform, three of them rated 10.0 on CVSS and exploitable, in certain circumstances, by an unauthenticated attacker.
ServiceNow deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, leaving organisations that run their own instances to apply the fixes themselves.
CVE-2026-18885 (CVSS 10.0) is a code injection vulnerability in the GraphQL Composite Data API that could enable an unauthenticated user to execute arbitrary code and gain access to, or modify, instance data.
CVE-2026-18886 (CVSS 10.0) is an improper access control vulnerability in the system configuration image upload processor that could enable an unauthenticated user to create or modify instance data, resulting in privilege escalation.
CVE-2026-74820 (CVSS 10.0) is a SQL injection vulnerability reached through a dynamic schema ORDER BY clause that could enable an unauthenticated user to execute arbitrary SQL statements against the instance's underlying database.
The three maximum-severity flaws share the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, describing a network-reachable attack of low complexity requiring no privileges and no user interaction, with high impact to confidentiality, integrity and availability in both the vulnerable component and the systems connected to it.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
2 articles · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
GitLab bundles a zero-click GraphQL flaw with a CSRF bug, and only one needs a victim1 distinct publisher
build
Keycloak's forgot-password flow hands over admin accounts, and the fix is a same-day call1 distinct publisher
build
One link, your session: F-RevoCRM XSS has no fix but 8.0.41 distinct publisher
build
A Commerce Cloud RCE chain reached a honeypot three days after the patch shipped1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One advisory, one outlet that read it
Every technical fact here originates in ServiceNow's August 27 advisory; the reporting is careful, but it is transcription plus scrutiny, not verification. Only The Hacker News went to the records themselves, and what it found there — a vendor description that says unauthenticated against a vector that says low privileges required, one affected-version row marked unknown — is the sort of thing that survives only when someone checks. Counting the syndicated duplicate as a third voice would flatter the sourcing.
Vendor fleet done, everyone else unmeasured
The only patch uptake anyone can point to is ServiceNow's own: it updated the instances it hosts and then, as both accounts confirm, handed the fix downstream. Nothing in this reporting measures how many self-hosted instances have installed it, and the footprint figure — 100,000 apps across 85% of the Fortune 500 — describes the platform's reach, not the patch's. Absent exploitation and absent public exploit code, the risk stays theoretical while the installation gap stays uncounted.
Three perfect tens, no attacker in sight
A 10.0 is the loudest number the scale offers, and here it is self-issued three times over, with no exploit code public, no catalog listing, and the vendor stating in each record that it sees no exploitation. Look at July for calibration: that flaw scored 9.5, differing from these by the single attack-complexity metric, and its one exploitation sighting turned out to be someone's proof-of-concept firing. The gap is in the framing, not the underlying risk — a network-reachable SQL injection needing no credentials deserves attention whatever the digit on the front.
The scorer is also the vendor
ServiceNow rates its own flaws, publishes its own advisory, patches its own fleet first, and — when exploitation was alleged in July — answered with a carefully bounded statement that it saw no evidence the activity touched instances it hosts. That is four roles in one party, and NIST's narrowed enrichment scope means no one is scheduled to second-guess any of them. The supporting cast has its own pulls: a threat-intelligence firm that announced exploitation before it had matched the captured traffic to a public proof-of-concept, a research firm whose disclosure timeline is part of its shop window, and trade coverage that signs off by promoting a security vendor's benchmark report.
Solid on what was published, blind on what follows
The published facts are firm: dates, identifiers, vectors, affected trains, and quotes are all checkable against one advisory and are reported consistently. What we cannot see is anything downstream — who has patched, how many instances sit outside ServiceNow's hosting, whether the 8.7 flaw needs credentials, and what 'unknown' means on that one Australia row. High confidence in the record, low confidence in the consequences.