cross-posted from: https://lemmy.world/post/51231462

🚨 Three new ServiceNow vulnerabilities carry the maximum CVSS 10.0 severity.

CVE-2026-18885: Code injection in the GraphQL Composite Data API, potentially enabling unauthenticated arbitrary code execution.

CVE-2026-18886: Improper access control in the system configuration image upload processor, potentially enabling privilege escalation and unauthorized data modification.

CVE-2026-74820: SQL injection through a dynamic ORDER BY clause, potentially allowing arbitrary SQL execution against the underlying database.

All three are rated network-reachable, low complexity, no privileges required and no user interaction.

ServiceNow has released patches. A separate CVE-2026-6876 sandbox escape is rated CVSS 8.7.