forkast.news • 1h
ServiceNow AI Platform: Systemic Infrastructure Risk via Triple CVSS 10.0 Vulnerabilities
ServiceNow has disclosed three critical vulnerabilities (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) in its AI Platform, each scoring CVSS 10.0. These flaws allow unauthenticated, zero-interaction attackers to perform remote code execution (RCE) and arbitrary SQL injection (SQLi) against the underlying database. The vulnerabilities enable full instance compromise, including unauthorized data modification and administrative privilege escalation. The risks are amplified by the integration of AI agent workflows, which expand the attack surface and potential blast radius. Remediation requires immediate application of security updates via advisory KB3152242 for both hosted and on-premise installations.