×

Three CVSS 10.0 Flaws, No Authentication Needed. Who In Your Organisation Is Applying That Patch?

On 27 August, ServiceNow published a security advisory covering four vulnerabilities in the AI Platform. Three of them scored a perfect 10.0. None of them need authentication, none need user interaction, and all three are rated low complexity to exploit. If you run ServiceNow self-hosted, the patch is your job, and the clock started two weeks ago.

What was disclosed

  • CVE-2026-18885, CVSS 10.0. Code injection allowing arbitrary code execution, with potential access to and modification of data.
  • CVE-2026-18886, CVSS 10.0. Improper access control allowing an attacker to create or modify arbitrary data and elevate privileges.
  • CVE-2026-74820, CVSS 10.0. SQL injection allowing arbitrary SQL statements against the underlying database, and access to instance data beyond what was intended.
  • CVE-2026-6876, CVSS 8.7. A sandbox escape, also exploitable without authentication.

ServiceNow patched its hosted instances directly. Hotfixes were released for self-hosted deployments across the Xanadu, Yokohama, Zurich and Australia release families. The company says it has no evidence of exploitation and that the issues came out of its own research and responsible disclosure programmes.

The split that matters

ServiceNow states it patched hosted instances. Self-hosted deployments need the hotfix applied by you. Either way, confirm remediation status against your own instance list rather than assuming it, particularly if you have multiple instances or any inherited from an acquisition.

The gap between disclosure and patching

Jason Brown, director of counter fraud operations at iCOUNTER, made the point sharply in SecurityWeek’s coverage. Self-hosted organisations now have to find, schedule and apply the patch themselves, and in many organisations that takes weeks rather than days. During those weeks an unauthenticated attacker with a working exploit has a real shot at systems sitting next to HR records, vendor onboarding and finance approvals. His advice was not to wait for the normal patch cycle and to confirm it is applied this week.

That advice was published on 31 August. It is nine days old.

Why I’m writing about this on a recruitment blog

Because “find, schedule and apply” is not a technical instruction. It is a description of a person, and in a lot of ServiceNow estates that person does not clearly exist.

ServiceNow platform security tends to fall between two teams. The security function owns vulnerability management but often has limited depth on the platform itself. The platform team owns the instance but sits inside IT service management, where security advisories are not the daily rhythm. So the advisory lands, both teams assume the other is handling it, and the patch cycle quietly absorbs something that needed to be treated as urgent.

The organisations that handle this well have one named person who owns ServiceNow platform security specifically. Not security in general. Not the platform in general. The overlap. And that is a genuinely awkward role to fill, because it needs someone who can read a ServiceNow advisory, understand what it touches in your configuration, and have the authority to force an out-of-cycle change.

Four questions worth asking this week

1. Are we hosted or self-hosted, and does everyone in the room agree? It sounds trivial. In organisations with multiple instances and a history of acquisitions, it frequently is not.

2. Who received the 27 August advisory, and what did they do with it? Not who should have received it. Who did.

3. Do we have a route to apply an emergency ServiceNow patch outside the normal change window? If the answer involves a CAB meeting three weeks out, you have found your problem.

4. Is ServiceNow platform security in anyone’s objectives? If it is not written down as someone’s responsibility, it is nobody’s.

The wider pattern

This is the third time this year the same shape has appeared. ServiceNow ships capability at pace, and the operational burden of running it safely lands on customers who have not resourced for it. The AI Platform is now the layer holding your workflow logic, your identity data and your audit trail. Three unauthenticated 10.0s in that layer is a serious thing, and the fact that it was found and fixed responsibly is genuinely reassuring. What is less reassuring is how many organisations will not have applied the hotfix by the end of this month.

If you are self-hosted and you cannot say with confidence that the patch is in, that is today’s job, not this quarter’s.

Need someone who owns the overlap between ServiceNow and security? It is one of the harder profiles in the market and we recruit for it regularly. We can tell you what it pays and how long it takes before you commit to a requisition. Talk to us.


Sources: ServiceNow security advisory, 27 August 2026 · SecurityWeek, 31 August 2026 · BankInfoSecurity, 1 September 2026

Do you need a ServiceNow developer, technical consultant or architect?

Roughly a third of the ServiceNow roles that land on my desk have the wrong title on them.

Not slightly wrong. Wrong in a way that costs the client six weeks and a rejected offer.

The job spec says developer. The interview questions are about integration design and platform governance. The salary band is set at developer level. The candidates who could actually do the work take one look at the money and pass, and the ones who fit the money can’t answer the questions.

Here is how we help clients sort it out before the advert goes live.

The three roles, in plain terms

Developer. Builds what has been specified. Flows, scripts, UI, catalogue items, integrations that someone else has designed. Give a good ServiceNow developer a clear ticket and they will close it. Ask them to sit in front of a CFO and challenge the business case for a Now Assist rollout, and you have put them in the wrong room.

Technical consultant. Sits between the client and the build. Runs the workshops, translates what the business says it wants into what the platform can actually do, then either builds it or hands it to developers. This is the role most people mean when they write “developer” in a job spec. It needs the technical depth of a developer plus the willingness to be in a room with stakeholders who disagree with each other.

Architect. Owns the shape of the platform. Instance strategy, data model, integration patterns, upgrade path, what goes on ServiceNow and what does not. An architect’s value is mostly in the things they stop you doing. If you have one instance, one module and a two-person team, you do not need one yet.

The question that usually settles it

When a client is not sure which one they need, we ask this: who decides how the work gets done?

If the answer is “we tell them what to build”, it is a developer.

If the answer is “we want them to work that out with the business”, it is a technical consultant.

If the answer is “we want them to tell us what we should be building at all”, it is an architect.

That one question resolves most of it in about thirty seconds on a call.

What goes wrong at each level

Hiring a developer when you need a consultant. The most common one. You get someone who builds exactly what the ticket says, and the tickets are wrong because nobody has run a proper workshop with the business. Six months in, the platform works and nobody uses it.

Hiring a consultant when you need a developer. Less damaging, more expensive. You have paid a premium for stakeholder skills you are not using, and the person gets bored. They usually leave inside a year, and their exit interview says “the work wasn’t what I expected”.

Hiring an architect too early. This one comes up when a business has bought a lot of ServiceNow and panicked. A strong architect with no team to direct and no scale to manage will spend three months writing standards documents and then start looking. Architects want complexity. If you cannot give them any, someone else will.

Not hiring an architect when you should have. Usually visible about two years in, when you have four integrations built four different ways, customisation nobody can explain, and an upgrade everyone is afraid of. That is the expensive version.

What this means for your job spec

A few things we ask clients to be specific about before we take a role to market:

Who writes the requirements? If the answer is the person you are hiring, say so in the advert. It changes who applies.

How many people will they work alongside? A consultant in a team of twelve is a different job from a consultant who is the entire ServiceNow function. Both are legitimate. Candidates need to know which one they are walking into.

Which modules, honestly. “ITSM plus a bit of HRSD” is a real answer and it is fine. “Full platform” when you mean ITSM makes experienced people suspicious.

What does the first six months look like? Greenfield implementation, BAU support, and rescuing a bad implementation attract very different people. The third one, done honestly, attracts more people than you would expect. Plenty of good consultants enjoy a mess.

Is the title negotiable? Sometimes the work is architect-level and the internal band is not. Say it early. We would rather find someone who wants the scope more than the title than lose a candidate at offer.

Where partners and customers differ

If you are a ServiceNow partner, your consultants need client-facing polish and the ability to move between three accounts in a week. Your developers need throughput.

If you are an end customer, the same titles mean something different. Your consultant will spend more time on internal politics than on discovery workshops, and your developer will be closer to the business than a partner-side developer ever gets.

Candidates know the difference. When a customer-side spec reads like a partner-side spec, it reads as though you have copied it from somewhere. Which, usually, you have.

Getting it right first time

Most of the mis-hires we get asked to fix were not skills failures. The person could do the job in the spec. The spec just described a job the business did not need.

Twenty minutes scoping the role properly before it goes live saves a lot more than twenty minutes.

If you are about to open a ServiceNow role and you are not certain which of the three it is, send me the spec and I will tell you what I think. No charge and no pitch attached.

Interviewing Techniques for ServiceNow Hiring Managers

Are you getting the most out of your ServiceNow interviews?

When people think about interviews, they usually focus on the candidate. The preparation, the pressure and the performance. But in reality, just as much responsibility sits with the hiring manager.

If your interview process is inconsistent, unstructured or rushed, you could easily miss out on strong ServiceNow talent or end up making the wrong hire. A good interview should help you assess capability properly while also giving the candidate confidence in your business.

Here are five practical ways to improve your ServiceNow interview process and get more value from every conversation.

The quality of your hire is often a reflection of the quality of your interview process.

1. Choose the right interview format

Face-to-face interviews are no longer the only option. In the ServiceNow market, many businesses now use video interviews, phone screening calls and remote final stage meetings as part of their hiring process.

Each format has its own strengths, so it is important to be deliberate about the approach you take.

  • In-person interviews: Great for building rapport and giving candidates a feel for your working environment. Make sure the setting is professional, welcoming and well organised.
  • Video interviews: Efficient and convenient, especially for hybrid or remote roles. Think carefully about your background, the platform you are using and how you come across on screen.
  • Phone interviews: Useful for early stage screening, but more limited when it comes to assessing communication style and presence.

The key is to choose a format that suits the role and then apply it consistently across your shortlist.

2. Avoid questions that can introduce bias

Unconscious bias can easily creep into interviews, often through casual conversation rather than formal questioning. Small talk might feel harmless, but it can influence your perception of a candidate in ways that have nothing to do with their ability to do the job.

For example, asking what someone did at the weekend may seem friendly enough, but if you happen to share similar interests or backgrounds, that can create an unintended connection that affects your judgement.

Keep your questions focused on experience, behaviours, delivery and suitability for the role. That will help you make fairer and more effective hiring decisions.

3. Use a clear interview structure

A structured interview process nearly always leads to better outcomes than an informal one. It helps candidates know what to expect and helps your team assess people more consistently.

For many ServiceNow roles, a sensible structure might include:

  • a first stage interview to assess experience, communication and overall fit
  • a second stage interview focused on technical depth, stakeholder management or relevant examples
  • a final discussion if needed before making the offer

It is also a good idea to have two people from the hiring company involved in the interview process. This helps reduce bias and gives you a more balanced view of each candidate.

For many employers, first and second stage interviews can easily be carried out over Teams or Zoom.

4. Standardise your questions

If you ask every candidate completely different questions, comparing them fairly becomes much harder. Standardised questions make it easier to assess people against the same criteria and reduce the risk of bias affecting your decision.

For each ServiceNow role, create competency-based questions that relate directly to the skills and behaviours needed for success. You might ask candidates to talk through examples of leadership, problem solving, teamwork, stakeholder management or project delivery.

It also helps to score answers against a simple framework, so you can compare candidates more objectively once the interviews are complete.

That said, structure should not mean rigidity. Good interviews still need room for follow-up questions where necessary.

Useful prompts include:

  • Tell me more about that decision
  • Why did you approach it that way?
  • What was the outcome?
  • What would you do differently next time?

5. Take notes and follow up properly

It is surprisingly easy to leave an interview feeling confident about a candidate, only to forget key details later. Taking notes during and immediately after the interview will give you a much more reliable record of what stood out.

Make sure you capture both positives and concerns, along with any scores from your standardised questions. That will make the final review process far more effective.

Notes are also useful when it comes to follow-up. A personalised response that refers back to something discussed in the interview shows professionalism and genuine interest. In a competitive ServiceNow market, that can make a real difference to candidate engagement.

Final thoughts

If your interviews are not giving you the insight or results you need, it may be time to review the process. Often, small changes in structure, questioning and follow-up can have a significant impact on the quality of your hiring decisions.

Working with a specialist ServiceNow recruitment company can also help. The right recruitment partner will do more than introduce candidates. They can also advise on interview structure, market expectations and the kinds of questions that will help you identify the right person more effectively.

At Linking Humans, we help ServiceNow partners and end users across the UK, Europe and North America hire permanent and contract professionals who can make a real impact.

If you would like to speak to us, use the request call back option at the top of this page or get in touch here.

Want our latest blogs delivered straight to your inbox? Just enter your details below.

Sign up to receive our latest blogs

This field is for validation purposes and should be left unchanged.
Name(Required)
What type of blogs are you interested in? (Please tick all that apply)(Required)

Let's get started

Talk to one of our consultants todays, if you're looking to register a vacancy and apply for a role.

Upload your CV

Submit CV

This field is for validation purposes and should be left unchanged.
Name(Required)
Max. file size: 2 GB.