YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0021

Incident record

ServiceNow patches two AI Platform flaws, both scored a flat ten

Severity
Critical
Status
Patched
Type
Agent Hijack
Target
ServiceNow AI Platform
Actor
researcher
CVE
CVE-2026-18885

What happened

ServiceNow disclosed two vulnerabilities in its AI Platform, both rated 10.0 critical on CVSS 4.0. One let an unauthenticated user run arbitrary code, the other let an unauthenticated user run arbitrary SQL against the underlying database, in each case reading or changing instance data beyond what was intended.

The second CVE is CVE-2026-74820. ServiceNow said it deployed the fix to hosted instances and supplied it to partners and self-hosted customers, and that it was not aware of exploitation. A pair of unauthenticated 10.0s in one platform on one day is unusual, and the exposure for self-hosted customers lasts as long as their own patching does.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026