Vulnerability
Published 2026-08-27
Verified 2026-09-19

ServiceNow Now Platform sandbox escape (CVE-2026-6876)

ServiceNow's 27 August 2026 CVE record (CNA title: Sandbox Escape in Now Platform) says it remediated a sandbox-escape issue that could allow an unauthenticated user to execute arbitrary code within the Now Platform and gain more access than intended. ServiceNow scored it 8.7 (CVSS 4.0; vector uses PR:L). Hosted instances received a vendor-deployed security update; partners and self-hosted customers were given the update. ServiceNow says it is not currently aware of malicious exploitation against ServiceNow instances. Self-hosted operators should apply the August 2026 CVE advisory updates (KB3152242). CNA-listed affected rows span Xanadu, Yokohama, Zurich and Australia patch families (including builds before Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b / Patch 13 Hot Fix 4, Zurich Patch 7b–12 hotfixes as listed, and Australia Patch 2–5 hotfixes as listed). Same-day desk cards cover the three CVSS 4.0 10.0 AI Platform issues (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820).

Product
ServiceNow Now Platform
Versions
CNA-listed Xanadu, Yokohama, Zurich and Australia patch-family builds before the hotfixes named on the CVE record (see KB3152242)
CVSS
(CVSS 4.0, ServiceNow CNA)
Exploited in Australia?
unknown
Patch to
Hosted: vendor already deployed the update. Self-hosted/partners: apply August 2026 CVE advisory updates (KB3152242)

Primary: CVE-2026-6876 (ServiceNow CNA) · Vendor: ServiceNow August 2026 CVE advisory (KB3152242) · CVE: CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, CVE-2026-74820 · CVE-2026-74820 (same-day AI Platform SQL injection, 10.0)

vulnerabilities cloud