ServiceNow has released security patches for three maximum-severity vulnerabilities in its AI Platform that could allow unauthenticated attackers to launch code injection, SQL injection, and privilege escalation attacks. The company disclosed the flaws in a Thursday advisory, warning customers who run self-hosted instances to update their systems. The AI Platform, formerly known as the Now Platform, is a cloud-based enterprise service that powers more than 100,000 AI applications at 85 percent of Fortune 500 companies.

The three critical flaws are tracked as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. The first is a code injection vulnerability that permits arbitrary code execution, the second is a code injection weakness that enables privilege escalation, and the third allows SQL injection attacks that can access or modify instance data. All three can be exploited by unauthenticated threat actors in low-complexity attacks that do not require user interaction.

ServiceNow also addressed a high-severity sandbox escape issue, tracked as CVE-2026-6876, affecting the same platform. That flaw could allow attackers with basic privileges to achieve remote code execution on targeted systems. The company stated that it is not currently aware of malicious exploitation against ServiceNow instances, but it recommended that customers promptly apply updates or upgrade to a patched release if they have not already done so.

While ServiceNow did not flag any of these newly patched vulnerabilities as actively exploited, the company has faced repeated attacks on its products in recent years. Two years ago, threat actors chained three ServiceNow flaws, CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217, using publicly available exploits to breach private firms and government agencies worldwide in data theft campaigns.

More recently, in July, threat intelligence firm Defused reported that attackers were exploiting another critical vulnerability, CVE-2026-6875, a pre-authentication sandbox escape in the ServiceNow AI Platform. ServiceNow also privately disclosed a security incident last month in which researchers or customer-led investigations used an unauthenticated access flaw through a vulnerable API endpoint to query data from customer instances.

For U.S. enterprises that rely on ServiceNow鈥檚 platform, these warnings underscore the importance of patch management, especially for internet-facing instances. The company鈥檚 advisory did not include details on whether any of the new vulnerabilities have been seen in the wild, but the recent history of targeted attacks on the platform highlights the risk. ServiceNow鈥檚 customer base includes a large portion of the Fortune 500, many of which are U.S. firms, making timely updates a priority.

More cybersecurity news from TechManNews.