# ServiceNow patches three maximum severity flaws inside its AI agent platform

> Source: <https://startupfortune.com/servicenow-patches-three-maximum-severity-flaws-inside-its-ai-agent-platform/>
> Published: 2026-08-30 03:38:59+00:00

*ServiceNow disclosed four security flaws on August 27, three of them scoring a perfect 10.0, in the same AI Platform enterprises are being asked to trust with agentic work.*

Zero credentials required. That's the detail that should stop you. CVE-2026-18885 and CVE-2026-18886 are both maximum severity, CVSS 10.0, bugs: the first is a code injection flaw in the GraphQL Composite Data API that lets an unauthenticated attacker run arbitrary code and read or rewrite instance data, and the second is an improper access control flaw in the system configuration image upload processor that lets an outsider create or alter data and escalate privileges. No login needed for either one. A third 10.0, CVE-2026-74820, is a SQL injection bug reachable through a dynamic schema ORDER BY clause, letting an attacker run arbitrary queries against the database behind the instance. The fourth, CVE-2026-6876, is a sandbox escape rated 8.7 in the Now Platform. ServiceNow's description says it could allow arbitrary code execution. Its own CVSS vector tells a different story: low privileges recorded, not none.

None of this stayed quiet for long. According to The Hacker News, ServiceNow published the advisory on August 27 and said the issues came through its internal security research and responsible disclosure program. BleepingComputer reported that the company patched the three maximum severity flaws in its cloud platform, while customers with self-hosted instances were told to secure them on their own. ServiceNow also said it wasn't aware of exploitation of the four August flaws when the advisory went out.

## Why this matters for AI agents

That's the good news, mostly. ServiceNow has already pushed updates to hosted instances and made fixes available to partners and self-hosted customers. The affected release families include Xanadu, Yokohama, Zurich, and Australia, with each requiring specific patched builds. If you run your own instance, don't treat that as housekeeping. Treat it as exposure.

ServiceNow runs the IT helpdesk, HR onboarding, customer service, and internal workflow plumbing for companies that can't afford messy software. This isn't a fringe tool. It's the platform behind the ticket you filed when your laptop broke, the approval chain for a reimbursement request, and the system your company chose because it was meant to be the safe, boring enterprise option.

[ServiceNow bets $40 million on an Indian AI banking startup to lock down enterprise agent governance](https://startupfortune.com/servicenow-bets-40-million-on-an-indian-ai-banking-startup-to-lock-down-enterprise-agent-governance/)

ServiceNow Ventures has taken a 5% stake in BusinessNext, an Indian AI banking software company, at a $700 million valuation. The $40 million deal is as much a distribution partnership as an investment, tying BusinessNext's AI agents into ServiceNow's AI Control Tower governance platform as the race to monitor and control enterprise agents... - [enterprise AI agent governance platform](https://startupfortune.com/servicenow-bets-40-million-on-an-indian-ai-banking-startup-to-lock-down-enterprise-agent-governance/) - [ServiceNow banking software investment 2026](https://startupfortune.com/servicenow-bets-40-million-on-an-indian-ai-banking-startup-to-lock-down-enterprise-agent-governance/)

Here's the part that should worry anyone paying attention to the AI agent trend. The AI Platform where CVE-2026-74820 lives isn't a side project. It's the product ServiceNow has been positioning as the place where autonomous agents do real work: triaging tickets, updating records, and executing workflows that used to need a person watching the screen. CSO Online's reporting made the same basic point, warning security teams to look beyond the ServiceNow instance itself to the credentials, APIs, and workflows the platform can reach.

Frankly, that's the whole story. Every enterprise software pitch now has someone promising that agents will run procurement, IT support, or customer service with less human supervision. ServiceNow has leaned into that promise with its own AI Platform. Then three 10.0 bugs appear, each described with low attack complexity, no required privileges, and no user interaction. No stolen password. No phishing email. Just a reachable weakness in software that may already sit close to a company's most useful internal systems.

This isn't ServiceNow's first uncomfortable month here. The Hacker News reported in July on CVE-2026-6875, a separate pre-authentication sandbox escape in the same broad platform family, after threat intelligence firm Defused initially said it was seeing exploitation activity and later corrected that the captured payload matched Searchlight Cyber's published proof of concept. Two rounds of serious AI Platform vulnerabilities inside two months should get a board's attention, even if the August batch has no confirmed exploitation.

## What to do now

None of this means ServiceNow is uniquely careless. Complex platforms carry complex attack surfaces, and finding your own bugs before customers are hit is the responsible version of the story. Credit where it's due. But AI-ready and AI-secure are not the same claim, and vendors have been far too happy to let those two phrases blur together in this year's sales decks.

The practical move is not complicated. Confirm which release family you run, check the exact fixed build, and apply the update if ServiceNow hasn't already done it for you. Then look past the patch note. If the platform can touch employee records, ticket histories, vendor workflows, access requests, or integration credentials, security teams need to review what those connections allow. And what logs would show if someone tried to abuse them.

If you're the executive being pitched an agentic rollout on top of any platform, don't stop at asking whether it can do the task. Who's allowed to reach it with zero credentials? What data can it change? And how fast would you know if the answer went wrong.

**Also read:** [Astera Labs Stock Soars 116% on Record AI Connectivity Chip Revenue](https://startupfortune.com/astera-labs-stock-soars-116-on-record-ai-connectivity-chip-revenue/) • [China Builds the World's Best Robot Bodies but Still Can't Give Them a Brain](https://startupfortune.com/china-builds-the-worlds-best-robot-bodies-but-still-cant-give-them-a-brain/) • [X Uncovers 200,000-Account Chinese Bot Farm Targeting US AI Data Centers](https://startupfortune.com/x-uncovers-200000-account-chinese-bot-farm-targeting-us-ai-data-centers/)

[ServiceNow beats Q2 revenue estimates with 22% growth as Now Assist AI deals surge 70%](https://startupfortune.com/servicenow-beats-q2-revenue-estimates-with-22-growth-as-now-assist-ai-deals-surge-70/)

ServiceNow reported Q2 2026 revenue beating the $3.92 billion consensus estimate, with multi-product Now Assist AI deals growing nearly 70% year over year. CEO Bill McDermott reiterated the company's $1.5 billion AI annual contract value target for 2026, giving enterprise software bulls their clearest data point yet that AI is producing durable... - [ServiceNow Q2 earnings beat revenue](https://startupfortune.com/servicenow-beats-q2-revenue-estimates-with-22-growth-as-now-assist-ai-deals-surge-70/) - [AI deals driving software revenue growth](https://startupfortune.com/servicenow-beats-q2-revenue-estimates-with-22-growth-as-now-assist-ai-deals-surge-70/)
