Three 10.0s in One Advisory. In the AI Platform.
ServiceNow's Aug 27 disclosure puts three unauthenticated, no-user-interaction, maximum-severity flaws inside the runtime that ships AI agents to 85% of the Fortune 500
On Aug 27, ServiceNow published KB3152242, an August CVE advisory naming four vulnerabilities. Three of them are rated CVSS 10.0 — the ceiling — and all three live in the ServiceNow AI Platform. All three are exploitable by an unauthenticated attacker. All three are low attack complexity. None require any user interaction.
Tier-1 press picked it up the same day and through Aug 28 — BleepingComputer, The Hacker News, CSO Online, GBHackers, and Techzine all carried it. ServiceNow says it is not currently aware of exploitation.
Three separate flaws hitting the top of the scale in one advisory is not a common shape. Three of them living in the same tenant's AI runtime is less common still. Two things are worth pulling out of the writeup.
What the three flaws actually do
Per the ServiceNow advisory and the Hacker News writeup:
- CVE-2026-18885 — code injection in the GraphQL Composite Data API. An unauthenticated caller can execute arbitrary code and read or modify instance data.
- CVE-2026-18886 — improper access control in the system configuration image upload processor. An unauthenticated caller can create or modify instance data, leading to privilege escalation.
- CVE-2026-74820 — SQL injection in the AI Platform. An unauthenticated caller can run arbitrary SQL against the underlying database.
A fourth flaw, CVE-2026-6876, was bundled in the same advisory at a lower severity.
Read those together and they line up as one exposure surface, not three. Code execution reaches the runtime. Access control fails on writes to platform state. SQL reaches the database that platform state lives in. Any one of the three lands attacker-controlled work inside the same tenant an AI agent is running in.
Why the AI Platform tier is the interesting substrate
The CSO Online coverage restates the deployment footprint: the ServiceNow AI Platform powers roughly 100,000 enterprise AI applications and is used by around 85% of Fortune 500 companies. That figure has been in ServiceNow's own materials for months. What Aug 27 adds is that this substrate is now the named location of three concurrent unauthenticated maximum-severity flaws.
The AI Platform is where the agent-visible artifacts live — workflow definitions, prompt libraries, tool bindings, connector credentials, and the instance data an agent reads on every invocation. When the vendor-shipped runtime beneath those artifacts has an unauthenticated code-injection path (CVE-2026-18885), the agent is not the boundary being violated. The runtime the agent trusts is.
This is the same architectural class as the Aug 25 NemoClaw disclosure that we wrote up earlier this week, only up one tier: there, a vendor-shipped local LLM runtime bound insecurely enough that a single web page could reach it. Here, a vendor-hosted enterprise-AI runtime shipped with three unauthenticated CVSS 10.0 flaws at once. The story in both cases is that the substrate the agent depends on is the substrate the attacker gets to touch, and the agent is downstream of the outcome.
The patch-parity note
BleepingComputer and the ServiceNow advisory both flag the tenancy split explicitly. Now-hosted (managed) instances have already been auto-patched. Self-hosted customers must apply the update themselves.
That is a public, per-tenancy-model exposure-window gap on a triple-10 disclosure. The interval between "hosted tenants patched" and "self-hosted tenants patched" is not a design assumption anymore — it is a specific interval measurable in whatever telemetry each self-hosted operator has.
Every self-hosted tenant that is still on a pre-Aug-27 build after the advisory dropped is holding three unauthenticated CVSS 10.0 flaws in the runtime under its AI agents.
What defenders can take from this
Three things fall out of the Aug 27 disclosure that are worth carrying forward.
First, the AI Platform tier is now a first-class attack surface with a name and a CVE bracket around it. Not the model. Not the agent. The runtime the agent runs on. Any security posture that has been treating "the AI platform" as an opaque managed dependency needs to re-treat it the way it treats a database, a queue, or a message broker: something with a CVE feed you subscribe to and a patch cadence you monitor.
Second, unauthenticated + low-complexity + no-user-interaction + CVSS 10.0 x3 is the shape that shows up in scanner output within days of the advisory. Live-exploited status is a matter of when, not whether, on flaws that shape. The MLflow CVE-2026-64849 already-tracked in this digest was exploited within hours of assignment. Self-hosted operators should treat the Aug 27 advisory as a patch-tonight event.
Third, the boundary the runtime is now known not to hold is instance-data integrity. Every agent action that reads from platform state on invocation — connector configs, workflow definitions, prompt libraries, tool bindings — is downstream of that boundary. Runtime behavioral observation of the agent is what closes the exposure window while patch application closes the reachability.
The takeaway
The August AI-security cycle has been full of coordinated, novel, hard-to-parse incidents — sandbox escapes, swarm coordination, persistent chat-template poisoning. The Aug 27 ServiceNow advisory is not any of those. It is three old-school code-injection and SQL-injection flaws sitting under the runtime that ships AI agents to 85% of the Fortune 500.
Both stories are true at the same time. The runtime beneath agentic AI is being compromised by the classic bug classes even while agentic AI itself is being compromised by novel ones. Defense-in-depth is the design assumption that survives both.
SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.