CVE-2026-18885: ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnera
Summary
ServiceNow fixed a code injection vulnerability (a flaw where attackers can insert and run harmful code) in its AI platform that could let unauthenticated users (people without login credentials) execute arbitrary code (run any commands they want) and access or change data they shouldn't have access to. ServiceNow has already deployed security updates to its hosted services and provided patches to partners and customers, with no known malicious attacks reported so far.
Solution / Mitigation
ServiceNow recommends that customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so. ServiceNow has deployed a security update to hosted instances and provided the update to partners and self-hosted customers.
Vulnerability Details
EPSS: 0.0%
August 27, 2026
Classification
Affected Vendors
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18885
First tracked: August 27, 2026 at 08:10 PM
Classified by LLM (prompt v3) · confidence: 85%