ServiceNow AI Platform security patch release (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, CVE-2026-6876)
Security Patch Release
Summary
Hide ▲
Show ▼
ServiceNow released patches for ServiceNow AI Platform flaws that could enable code injection, SQL injection, privilege escalation, and sandbox escape attacks across cloud and self-hosted instances. The advisory covered CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, with CVE-2026-6876 fixed in the same release. ServiceNow said it was not aware of active malicious exploitation and urged customers to promptly apply updates or upgrade to patched releases.
Related Happenings
Microsoft security patch release for CVE-2026-68820
Security Patch Release
H score28
First: 12.08.2026 00:28
Last: 12.08.2026 00:28
Sources 1
About this happening:
Microsoft released August 2026 Patch Tuesday updates for Windows operating systems and supported software, fixing at least 398 vulnerabilities. The bundle includes...
Microsoft security patch release for CVE-2026-68820
Security Patch ReleaseAbout this happening: Microsoft released August 2026 Patch Tuesday updates for Windows operating systems and supported software, fixing at least 398 vulnerabilities. The bundle includes...
Adobe security patch release for CVE-2026-48362
Security Patch Release
H score43
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48362
Security Patch ReleaseAbout this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
TeamCity security patch release for CVE-2026-63077
Security Patch Release
H score53
First: 28.07.2026 11:11
Last: 28.07.2026 11:11
Sources 1
About this happening:
JetBrains released TeamCity On-Premises fixes for CVE-2026-63077, a critical unauthenticated remote code execution issue, through 2025.11.7, 2026.1.3, and...
TeamCity security patch release for CVE-2026-63077
Security Patch ReleaseAbout this happening: JetBrains released TeamCity On-Premises fixes for CVE-2026-63077, a critical unauthenticated remote code execution issue, through 2025.11.7, 2026.1.3, and...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
H score55
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch ReleaseAbout this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
ServiceNow security patch release for CVE-2026-6875
Security Patch Release
H score47
First: 20.07.2026 12:29
Last: 20.07.2026 12:29
Sources 1
About this happening:
ServiceNow released CVE-2026-6875 security updates for the ServiceNow AI Platform, covering hosted and self-hosted instances. The patch addresses a pre-auth sand...
ServiceNow security patch release for CVE-2026-6875
Security Patch ReleaseAbout this happening: ServiceNow released CVE-2026-6875 security updates for the ServiceNow AI Platform, covering hosted and self-hosted instances. The patch addresses a pre-auth sand...
Timeline
-
28.08.2026 13:29 2 articles · 1h ago
ServiceNow patches three max-severity AI Platform flaws and a sandbox escape issue
Mitigation Patch UpdateServiceNow released security patches for CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820 in the cloud-based ServiceNow AI Platform and also addressed CVE-2026-6876, a high-severity sandbox escape that could let attackers with basic privileges gain remote code execution on targeted systems. The company said it was not currently aware of malicious exploitation against ServiceNow instances and urged customers to promptly apply updates or upgrade to a patched release, including self-hosted instances.
Show sources
- ServiceNow warns of three max severity security vulnerabilities — www.bleepingcomputer.com — 28.08.2026 13:29
- ServiceNow warns of three max severity security vulnerabilities — www.bleepingcomputer.com — 28.08.2026 13:29