THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18885 — ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, insta

[NVD] CVE-2026-18885 — ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, insta

mednvdPublished 2026-08-27

CVE-2026-18885 CVSS: None Published: 2026-08-27T20:17:03.870

ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended. 

ServiceNow deplo

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18885