×

Three CVSS 10.0 Flaws, No Authentication Needed. Who In Your Organisation Is Applying That Patch?

On 27 August, ServiceNow published a security advisory covering four vulnerabilities in the AI Platform. Three of them scored a perfect 10.0. None of them need authentication, none need user interaction, and all three are rated low complexity to exploit. If you run ServiceNow self-hosted, the patch is your job, and the clock started two weeks ago.

What was disclosed

  • CVE-2026-18885, CVSS 10.0. Code injection allowing arbitrary code execution, with potential access to and modification of data.
  • CVE-2026-18886, CVSS 10.0. Improper access control allowing an attacker to create or modify arbitrary data and elevate privileges.
  • CVE-2026-74820, CVSS 10.0. SQL injection allowing arbitrary SQL statements against the underlying database, and access to instance data beyond what was intended.
  • CVE-2026-6876, CVSS 8.7. A sandbox escape, also exploitable without authentication.

ServiceNow patched its hosted instances directly. Hotfixes were released for self-hosted deployments across the Xanadu, Yokohama, Zurich and Australia release families. The company says it has no evidence of exploitation and that the issues came out of its own research and responsible disclosure programmes.

The split that matters

ServiceNow states it patched hosted instances. Self-hosted deployments need the hotfix applied by you. Either way, confirm remediation status against your own instance list rather than assuming it, particularly if you have multiple instances or any inherited from an acquisition.

The gap between disclosure and patching

Jason Brown, director of counter fraud operations at iCOUNTER, made the point sharply in SecurityWeek’s coverage. Self-hosted organisations now have to find, schedule and apply the patch themselves, and in many organisations that takes weeks rather than days. During those weeks an unauthenticated attacker with a working exploit has a real shot at systems sitting next to HR records, vendor onboarding and finance approvals. His advice was not to wait for the normal patch cycle and to confirm it is applied this week.

That advice was published on 31 August. It is nine days old.

Why I’m writing about this on a recruitment blog

Because “find, schedule and apply” is not a technical instruction. It is a description of a person, and in a lot of ServiceNow estates that person does not clearly exist.

ServiceNow platform security tends to fall between two teams. The security function owns vulnerability management but often has limited depth on the platform itself. The platform team owns the instance but sits inside IT service management, where security advisories are not the daily rhythm. So the advisory lands, both teams assume the other is handling it, and the patch cycle quietly absorbs something that needed to be treated as urgent.

The organisations that handle this well have one named person who owns ServiceNow platform security specifically. Not security in general. Not the platform in general. The overlap. And that is a genuinely awkward role to fill, because it needs someone who can read a ServiceNow advisory, understand what it touches in your configuration, and have the authority to force an out-of-cycle change.

Four questions worth asking this week

1. Are we hosted or self-hosted, and does everyone in the room agree? It sounds trivial. In organisations with multiple instances and a history of acquisitions, it frequently is not.

2. Who received the 27 August advisory, and what did they do with it? Not who should have received it. Who did.

3. Do we have a route to apply an emergency ServiceNow patch outside the normal change window? If the answer involves a CAB meeting three weeks out, you have found your problem.

4. Is ServiceNow platform security in anyone’s objectives? If it is not written down as someone’s responsibility, it is nobody’s.

The wider pattern

This is the third time this year the same shape has appeared. ServiceNow ships capability at pace, and the operational burden of running it safely lands on customers who have not resourced for it. The AI Platform is now the layer holding your workflow logic, your identity data and your audit trail. Three unauthenticated 10.0s in that layer is a serious thing, and the fact that it was found and fixed responsibly is genuinely reassuring. What is less reassuring is how many organisations will not have applied the hotfix by the end of this month.

If you are self-hosted and you cannot say with confidence that the patch is in, that is today’s job, not this quarter’s.

Need someone who owns the overlap between ServiceNow and security? It is one of the harder profiles in the market and we recruit for it regularly. We can tell you what it pays and how long it takes before you commit to a requisition. Talk to us.


Sources: ServiceNow security advisory, 27 August 2026 · SecurityWeek, 31 August 2026 · BankInfoSecurity, 1 September 2026

ServiceNow Eyes $7 Billion Acquisition of Cybersecurity Startup Armis

ServiceNow is reportedly in advanced discussions to acquire Armis, a San Francisco-based cybersecurity startup, in a deal valued at approximately $7 billion. This acquisition would mark one of ServiceNow’s most significant strategic moves as the workflow automation giant continues to expand its security capabilities and strengthen its position in the enterprise technology market.

About Armis

Founded in 2015 by Yevgeny Dibrov and Nadir Izrael, both Israel Institute of Technology graduates with backgrounds in the Israel Defence Forces software units, Armis has become a leader in cybersecurity asset management. The company’s flagship Centrix platform provides real-time visibility, risk assessment, and protection across an organisation’s entire digital attack surface.

Armis has demonstrated impressive growth, reaching $300 million in annual recurring revenue earlier this year, up from $200 million the previous year. The company was last valued at $6.1 billion following a $435 million funding round in November 2024. Its client roster includes major organisations such as Colgate-Palmolive, United Airlines, and NHS South Wales.

Strategic Implications

This acquisition aligns with ServiceNow’s aggressive expansion strategy in the security space. Earlier this month, ServiceNow acquired identity security startup Veza for an undisclosed sum, and in March, the company purchased AI firm Moveworks. The potential Armis deal represents ServiceNow’s commitment to building a comprehensive security portfolio that complements its workflow automation platform.

For ServiceNow professionals and organisations invested in the ecosystem, this acquisition signals continued innovation and expansion of security capabilities within the platform. As the deal nears completion, industry watchers expect the integration of Armis’s technology to enhance ServiceNow’s security offerings and create new opportunities for implementation and specialisation.

The deal is expected to be announced within days, pending final negotiations.

Let's get started

Talk to one of our consultants todays, if you're looking to register a vacancy and apply for a role.

Upload your CV

Submit CV

This field is for validation purposes and should be left unchanged.
Name(Required)
Max. file size: 2 GB.