Skip to content
Breaking
Dutch court jails man for life over role in Rwanda genocideServiceNow fixes three critical AI Platform flawsWindows 11 KB5120998 preview update arrives with 35 fixes and UI tweaksHow the Sales and Purchase Agreement worksAsia’s inflation scare easing despite hotter printsNepal and China restart flood rescues after upstream lake threat easesAPT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic OrganizationsSembcorp Industries' India unit IPO could raise group value by up to 10%PaperCut zero-day under active exploit in all versionsIndonesia stocks slip 0.06% as Fed, BI leadership weigh on marketNTT earthquake victims to receive free medical care funded by BNPBAvaland posts 41% quarterly net profit rise after strong salesIndonesia urges community-led reconstruction for quake-hit NTT homesBelgian startup Any raises €10 million for production of LUV1 electric motorcycleRoad accidents and injuries rise in first half of 2026 despite fewer deathsMah Sing lifts 2Q net profit 9.8% as revenue jumps 16%Startup community gathers in New York on September 10 to debate AI-driven business modelsWe need to decide if the given headline is already fluent natural English. The headline: "No, Mark Zuckerberg, the future is not (yet) for everyone". This seems a bit odd: "No, Mark Zuckerberg, the future is not (yet) for everyone". It reads like a response to Mark Zuckerberg? The phrase "No, Mark Zuckerberg, the future is not (yet) for everyone" is somewhat awkward. Usually you'd say "No, Mark Zuckerberg, the future is not yet for everyone" or "No, Mark Zuckerberg: the future is not (yet) for everyone". The parentheses around "yet" maybe okay. But the phrase "No, Mark Zuckerberg, the future is not (yet) for everyone" is a bit unnatural. It could be interpreted as addressing Mark Zuckerberg: "No, Mark Zuckerberg, the future is not (yet) for everyone". That is a direct address, but the comma after Zuckerberg is correct for direct address: "No, Mark Zuckerberg, the future is not (yet) for everyone". Actually direct address: "No, Mark Zuckerberg, the future is not (yet) for everyone." That is grammatical: youVirtual power plant pilot in Malaysia serves fewer than 1,000 households after three yearsMalaysia Secures RM218.5 Billion Approved Investments in 1H 2026, Jobs Rise 8.4%Dutch court jails man for life over role in Rwanda genocideServiceNow fixes three critical AI Platform flawsWindows 11 KB5120998 preview update arrives with 35 fixes and UI tweaksHow the Sales and Purchase Agreement worksAsia’s inflation scare easing despite hotter printsNepal and China restart flood rescues after upstream lake threat easesAPT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic OrganizationsSembcorp Industries' India unit IPO could raise group value by up to 10%PaperCut zero-day under active exploit in all versionsIndonesia stocks slip 0.06% as Fed, BI leadership weigh on marketNTT earthquake victims to receive free medical care funded by BNPBAvaland posts 41% quarterly net profit rise after strong salesIndonesia urges community-led reconstruction for quake-hit NTT homesBelgian startup Any raises €10 million for production of LUV1 electric motorcycleRoad accidents and injuries rise in first half of 2026 despite fewer deathsMah Sing lifts 2Q net profit 9.8% as revenue jumps 16%Startup community gathers in New York on September 10 to debate AI-driven business modelsWe need to decide if the given headline is already fluent natural English. The headline: "No, Mark Zuckerberg, the future is not (yet) for everyone". This seems a bit odd: "No, Mark Zuckerberg, the future is not (yet) for everyone". It reads like a response to Mark Zuckerberg? The phrase "No, Mark Zuckerberg, the future is not (yet) for everyone" is somewhat awkward. Usually you'd say "No, Mark Zuckerberg, the future is not yet for everyone" or "No, Mark Zuckerberg: the future is not (yet) for everyone". The parentheses around "yet" maybe okay. But the phrase "No, Mark Zuckerberg, the future is not (yet) for everyone" is a bit unnatural. It could be interpreted as addressing Mark Zuckerberg: "No, Mark Zuckerberg, the future is not (yet) for everyone". That is a direct address, but the comma after Zuckerberg is correct for direct address: "No, Mark Zuckerberg, the future is not (yet) for everyone". Actually direct address: "No, Mark Zuckerberg, the future is not (yet) for everyone." That is grammatical: youVirtual power plant pilot in Malaysia serves fewer than 1,000 households after three yearsMalaysia Secures RM218.5 Billion Approved Investments in 1H 2026, Jobs Rise 8.4%
AI Edge

ServiceNow fixes three critical AI Platform flaws

ServiceNow patched three new maximum-severity vulnerabilities in its AI Platform that allowed unauthenticated attackers to run arbitrary code, escalate privileges and inject SQL without user interaction.

Source: BleepingComputer · August 28, 2026 at 10:32 AM · AI-assisted report

Single-source
ServiceNow fixes three critical AI Platform flaws
Photo: Wikimedia Commons — ServiceNow

KUALA LUMPUR, 28 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Share

ServiceNow Issues Urgent Patches for Three Critical AI Platform Vulnerabilities

Market Impact

ServiceNow has released security updates to address three newly disclosed maximum-severity vulnerabilities in its AI Platform, which could enable code injection, SQL injection, and privilege escalation attacks. The flaws—tracked as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820—affect the cloud-based platform, widely used by enterprises for AI-driven workflow integration. ServiceNow has urged customers to apply the patches immediately, particularly for self-hosted instances.

The ServiceNow AI Platform, formerly known as the Now Platform, serves as a core enterprise PaaS solution, supporting over 100,000 AI applications and used by 85% of Fortune 500 companies. The first vulnerability (CVE-2026-18885) allows arbitrary code execution via code injection, while CVE-2026-18886 enables privilege escalation. The third flaw (CVE-2026-74820) permits unauthorized access or modification of instance data through SQL injection. All three can be exploited by unauthenticated attackers in low-complexity attacks without requiring user interaction. ServiceNow patched a high-severity sandbox escape issue (CVE-2026-6876), which could allow attackers with basic privileges to achieve remote code execution.

ServiceNow stated it is not aware of any active exploitation of these vulnerabilities but emphasized the importance of applying updates promptly. The company’s advisory follows a pattern of recurring security challenges in its platform. In 2024, threat actors exploited a chain of three ServiceNow flaws (CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217) to breach private firms and government agencies globally. More recently, in July 2026, researchers reported attacks leveraging CVE-2026-6875, another critical pre-authentication sandbox escape vulnerability in the AI Platform.

The recurring nature of these vulnerabilities underscores the persistent risks associated with enterprise cloud platforms. ServiceNow also disclosed a separate security incident last month, where an unauthenticated access flaw via a vulnerable API endpoint allowed researchers or customers to query data from instances. Industry analysis suggests that while prevention scores may appear strong initially, effectiveness declines sharply once attackers gain valid credentials, highlighting the need for continuous monitoring and access controls.

For Malaysian enterprises relying on ServiceNow’s AI Platform, the immediate priority is to apply the latest patches to mitigate exposure to these critical vulnerabilities. Given the platform’s widespread adoption among large corporations, including those with regional operations, local IT teams should prioritize vulnerability assessments and ensure compliance with ServiceNow’s security advisories. The company’s proactive disclosure of these issues reflects growing scrutiny of cloud security practices, particularly in AI-driven enterprise environments.

The outlook remains cautious, as threat actors continue to target enterprise cloud platforms with increasing sophistication. ServiceNow’s rapid response in patching these flaws demonstrates industry responsiveness, but organizations must remain vigilant in applying updates and reinforcing security postures. Further developments, including potential exploitation attempts, will likely shape future security protocols for AI-powered enterprise systems in Malaysia and beyond.

Related: ServiceNow

Reporting based on BleepingComputer. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.