ServiceNow CVE-2026-74820
ServiceNow Security Vulnerability
Unverified. The per-release patch levels below are an auto-import (NVD + GitHub Advisory Database) and have not yet been confirmed against the login-gated ServiceNow KB. The exposure check returns NEEDS REVIEW for this advisory — review the references and your current patch level.
Risk & exploitation
No EPSS score is published for this CVE yet; priority uses the available signals. Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended.
ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances.
We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Auto-generated stub (GitHub Advisory Database + NVD index). Per-release fixed-in and detection signals are pending manual verification; untilingest_status: readythe Layer-1 check returns NEEDS REVIEW (badged Unverified), and until a signal carries a verifiedmatchthe exposure check returns DORMANT/INVESTIGATE — never a false PATCHED or EXERCISED.
Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Australia | Patch 2 Hot Fix 3 / Patch 3m / Patch 3 Hot Fix 2 / Patch 4 / Patch 5 |
| Zurich | Patch 7b Hot Fix 3 / Patch 8 Hot Fix 5 / Patch 9 Hot Fix 6 / Patch 10 Hot Fix 2m (m-branch) / Patch 10 Hot Fix 3 (standard) / Patch 11 / Patch 12 |
| Yokohama | Patch 12 Hot Fix 3b / Patch 13 Hot Fix 4 |
| Xanadu | Patch 11 Hot Fix 7a |
Source & attribution
Per-release fixed-in auto-drafted from the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[] boundaries, https://cveawg.mitre.org/api/cve/CVE-2026-74820 (auto-synced 2026-08-28). The same patch matrix is in the login-gated ServiceNow KB; the public CVE Record is the citable source. Verify the matrix before flipping ingest_status to ready.
References
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.