Security NEXTAugust 28, 2026🇯🇵Translated from Japanese

ServiceNow Patches Multiple Critical Vulnerabilities in Now Platform and AI Platform

ServiceNow has disclosed multiple critical vulnerabilities in the Now Platform and ServiceNow AI Platform, prompting the immediate release of patched versions.

The company published a security advisory on August 27 detailing four CVEs: CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820.

CVE-2026-18885 affects the GraphQL Composite Data API in the ServiceNow AI Platform. Under specific conditions, the flaw permits unauthenticated attackers to execute arbitrary code, enabling them to view and modify instance data.

CVE-2026-18886 stems from insufficient access controls in the system configuration image upload process. Attackers can create or alter data and escalate privileges without authentication.

Additionally, CVE-2026-74820 is an SQL injection vulnerability that allows unauthenticated execution of arbitrary SQL commands against the backend database, potentially exposing or modifying sensitive records.

ServiceNow urges customers to apply the latest updates immediately to mitigate the risks.

Related articles

Security NEXTVulnerabilities & Exploits

CISA Adds Linux Kernel Frag Gap Flaw and Two Other Exploited Vulnerabilities to KEV Catalog

The US Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 27, 2026. One of the entries is CVE-2026-53362, a high-severity privilege escalation issue in the Linux kernel also known as Frag Gap. The flaw stems from an out-of-bounds write when generating IPv6 packets, allowing a low-privileged user to obtain root access. The Linux Kernel Organization assigned it a CVSS v3.1 base score of 7.8 and rated it High severity, with public exploit code already available. Federal agencies must remediate CVE-2026-53362 and CVE-2023-49105 by the August 30 deadline. The advisory underscores ongoing exploitation of these issues in the wild.

HispasecVulnerabilities & Exploits

CISA Adds Six Actively Exploited Vulnerabilities to KEV Catalog Including Citrix NetScaler, Linux Kernel and Microsoft SQL Server Flaws

On August 26, 2026, CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling confirmed active exploitation and requiring immediate remediation priority. The batch includes a recent memory corruption issue in Citrix NetScaler ADC and NetScaler Gateway tracked as CVE-2026-8452, along with five older flaws affecting Microsoft SQL Server, the Linux kernel, Ajax.NET Professional, Red Hat libuser, and Red Hat ABRT. Citrix released patches for the NetScaler vulnerability on June 30, 2026, while CISA set an August 29, 2026 deadline for federal agencies. Real-world attacks have already deployed web shells and performed reconnaissance after successful exploitation of the Citrix appliance. The remaining CVEs enable remote code execution, local privilege escalation, and denial-of-service conditions across widely deployed enterprise technologies.

BoletimSecVulnerabilities & Exploits

Next.js Patches Two Critical RCE Vulnerabilities in Versions 15.5.24 and 16.3.3

Next.js has released security updates to address two critical vulnerabilities that could allow unauthenticated remote code execution. The fixes are available in versions 15.5.24 and 16.3.3. The first issue, tracked as CVE-2026-75604 with a CVSS score of 9.0, affects applications hosted on Windows servers using Pages Router or App Router without Cache Components and stems from a path traversal flaw. The second vulnerability impacts the Image Optimization API when processing malicious AVIF files, enabling code execution through crafted image inputs. Both flaws affect a wide range of versions from 10.0.0 and 13.4 onward. Administrators are advised to update immediately, rebuild containers, and verify production environments run the patched releases, especially on Windows systems and those handling user-uploaded images.

Security NEXTVulnerabilities & Exploits

Multiple Vulnerabilities Found in Apache Tomcat, Four Rated Critical by CISA

Apache Tomcat has received updates addressing 11 vulnerabilities across versions 11.0.25, 10.1.59, and 9.0.121. The Apache Software Foundation rated four issues as Important, while CISA assigned Critical severity to four CVEs based on CVSS v3.1 scores reaching 9.8. The flaws include authentication bypasses, access control evasion due to path evaluation order, off-by-one errors, and HTTP/2 resource leaks leading to denial of service. One vulnerability was disclosed earlier in July, with the remaining ten detailed on August 25. Moderate and Low severity issues were also patched in the same releases. The discrepancies in severity ratings between the vendor and CISA highlight differing risk assessments for the same CVEs.