Tools AI Risk Radar ai-incident-0021
Incident record
ServiceNow patches two AI Platform flaws, both scored a flat ten
- Severity
- Critical
- Status
- Patched
- Type
- Agent Hijack
- Target
- ServiceNow AI Platform
- Actor
- researcher
- CVE
- CVE-2026-18885
What happened
ServiceNow disclosed two vulnerabilities in its AI Platform, both rated 10.0 critical on CVSS 4.0. One let an unauthenticated user run arbitrary code, the other let an unauthenticated user run arbitrary SQL against the underlying database, in each case reading or changing instance data beyond what was intended.
The second CVE is CVE-2026-74820. ServiceNow said it deployed the fix to hosted instances and supplied it to partners and self-hosted customers, and that it was not aware of exploitation. A pair of unauthenticated 10.0s in one platform on one day is unusual, and the exposure for self-hosted customers lasts as long as their own patching does.
Sources
- NVD record, CVE-2026-18885nvd.nist.gov/vuln/detail/CVE-2026-18885
- NVD record, CVE-2026-74820nvd.nist.gov/vuln/detail/CVE-2026-74820
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026