ServiceNow’s CVSS 10.0 trio shows how one platform patch cycle becomes everyone’s third-party risk problem
Four flaws hand just been disclosed in ServiceNow's AI Platform, three of them scored a maximum CVSS 10.0: a code injection bug in the GraphQL Composite Data API (CVE-2026-18885), a privilege escalation flaw in the system configuration image upload…