ServiceNow Now Platform sandbox escape (CVE-2026-6876)
ServiceNow's 27 August 2026 CVE record (CNA title: Sandbox Escape in Now Platform) says it remediated a sandbox-escape issue that could allow an unauthenticated user to execute arbitrary code within the Now Platform and gain more access than intended. ServiceNow scored it 8.7 (CVSS 4.0; vector uses PR:L). Hosted instances received a vendor-deployed security update; partners and self-hosted customers were given the update. ServiceNow says it is not currently aware of malicious exploitation against ServiceNow instances. Self-hosted operators should apply the August 2026 CVE advisory updates (KB3152242). CNA-listed affected rows span Xanadu, Yokohama, Zurich and Australia patch families (including builds before Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b / Patch 13 Hot Fix 4, Zurich Patch 7b–12 hotfixes as listed, and Australia Patch 2–5 hotfixes as listed). Same-day desk cards cover the three CVSS 4.0 10.0 AI Platform issues (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820).
- Product
- ServiceNow Now Platform
- Versions
- CNA-listed Xanadu, Yokohama, Zurich and Australia patch-family builds before the hotfixes named on the CVE record (see KB3152242)
- CVSS
- (CVSS 4.0, ServiceNow CNA)
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- Hosted: vendor already deployed the update. Self-hosted/partners: apply August 2026 CVE advisory updates (KB3152242)
Primary: CVE-2026-6876 (ServiceNow CNA) · Vendor: ServiceNow August 2026 CVE advisory (KB3152242) · CVE: CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, CVE-2026-74820 · CVE-2026-74820 (same-day AI Platform SQL injection, 10.0)
