Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

ServiceNow AI platform code injection and SQL injection vulnerabilities

ServiceNow remediated two vulnerabilities in its AI platform: a code injection flaw and a SQL injection flaw, both allowing unauthenticated users to execute arbitrary code or SQL statements and access or modify instance data. No malicious exploitation has been reported.

Disclosed 27 August 2026 · Record updated 13 September 2026

Impact

Unauthenticated users could execute arbitrary code or SQL statements and gain access to or modify instance data in affected instances

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-18885
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-74820