
ServiceNow Ships Three CVSS 10.0 Pre-Auth Flaws Affecting Xanadu, Yokohama, Zurich Self-Hosted Instances
ServiceNow patched three CVSS 10.0 unauthenticated flaws on 27 Aug 2026 but left self-hosted customers to apply fixes. Prior CVE-2026-6875 saw in-the-wild attempts; rating inconsistencies and missing KEV entries highlight exposure gaps. Self-hosted operators face immediate remote code and SQL risks.
The three maximum-severity issues join CVE-2026-6875, a sandbox escape reported by Searchlight Cyber on 1 April and observed in the wild by Defused in July. ServiceNow states it has applied fixes to hosted instances but self-hosted customers must install the listed hot fixes themselves. No entries appear in CISA KEV as of 28 August, leaving only vendor severity data on record. The rapid succession of pre-auth network-reachable flaws after the July disclosure indicates systemic gaps in input handling across GraphQL, configuration processors, and schema layers. ServiceNow's own CVSS vectors list low attack complexity for the new trio yet high complexity for the prior sandbox escape despite near-identical metrics; this internal inconsistency is unexplained in the advisory. Procurement records show ServiceNow continues to win large federal contracts while shifting patch responsibility to operators, creating a measurable gap between hosted and on-premise exposure. Independent confirmation of exploitation remains limited to the July CVE; the new flaws carry no public PoC but share identical unauthenticated network vectors. Self-hosted instances running any Xanadu, Yokohama, or Zurich build before the specified hot fixes remain exposed to unauthenticated remote code execution and arbitrary SQL. Operators should treat the three CVEs as priority-one regardless of KEV status and verify patch application through contract-mandated logging. Next 30 days will show whether CISA adds any to the Known Exploited Vulnerabilities catalog or if further vendor disclosures follow the same pattern.
CISA: At least one new CVE enters KEV within 30 days of 28 Aug 2026.
Sources (2)
- [1]ServiceNow Security Advisory(https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1234567)
- [2]Searchlight Cyber Disclosure Timeline(https://searchlightcyber.com/blog/servicenow-6875)