CVE-2026-74820: ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulne
Summary
ServiceNow fixed a SQL injection vulnerability (a flaw that lets attackers run unauthorized database commands) in its AI platform that could have let unauthenticated users access or change data they shouldn't be able to. The company deployed security updates to its hosted systems and provided patches to partners and self-hosted customers, with no known malicious attacks reported so far.
Solution / Mitigation
ServiceNow recommends that customers "promptly apply appropriate updates or upgrade to a patched release if they have not already done so." Security updates have been deployed to hosted instances, and patches are available to partners and self-hosted customers.
Vulnerability Details
EPSS: 0.0%
August 27, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-74820
First tracked: August 27, 2026 at 08:10 PM
Classified by LLM (prompt v3) · confidence: 85%