🚨 Three new ServiceNow vulnerabilities carry the maximum CVSS 10.0 severity.
CVE-2026-18885: Code injection in the GraphQL Composite Data API, potentially enabling unauthenticated arbitrary code execution.
CVE-2026-18886: Improper access control in the system configuration image upload processor, potentially enabling privilege escalation and unauthorized data modification.
CVE-2026-74820: SQL injection through a dynamic ORDER BY clause, potentially allowing arbitrary SQL execution against the underlying database.
All three are rated network-reachable, low complexity, no privileges required and no user interaction.
ServiceNow has released patches. A separate CVE-2026-6876 sandbox escape is rated CVSS 8.7.
You must log in or register to comment.

