🔥 この記事の詳細
2026-08-28 更新
B
今週中

ServiceNowの「Now Platform」および「ServiceNow AI Platform」において、複数の深刻な脆弱性

脆弱性📰 2記事🌐 2 countries
🇯🇵 Japan · 🇺🇸 US
🖥️ 製品ServiceNow
🔢 CVECVE-2026-18885CVE-2026-6876CVE-2026-18886+1件
📅 2026-08-28📰 secnext
📌 一言でいうと
ServiceNowの「Now Platform」および「ServiceNow AI Platform」において、複数の深刻な脆弱性が公開されました。認証なしで任意のコード実行が可能なコードインジェクション(CVE-2026-18885)や、権限昇格につながるアクセス制御不備(CVE-2026-18886)、および任意のSQL実行が可能なSQLインジェクション(CVE-2026-74820)が含まれています。ベンダーより修正版が公開されており、迅速な適用が推奨されます。
🔍該当判定
  • 社内で「ServiceNow」を導入して利用している
  • 「Now Platform」を業務管理やITサービス管理に利用している
  • 「ServiceNow AI Platform」を導入し、AI機能を活用している
上記いずれにも該当しない → 静観でOK
該当時の対応
ServiceNowが提供する最新のセキュリティパッチを適用し、修正版へアップデートしてください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】ServiceNow 複数クリティカル脆弱性 (CVE-2026-18885 他) 対応について

お疲れさまです。ServiceNow製品の深刻な脆弱性に関する情報共有です。

■ 概要
ServiceNowのプラットフォームにおいて、認証なしで任意のコード実行やSQL実行、権限昇格が可能な複数のクリティカルな脆弱性が判明しました。特にCVE-2026-18885およびCVE-2026-74820は、外部から認証なしにデータ操作が行われるリスクがあり、極めて危険です。

■ 影響範囲
- ServiceNow Now Platform
- ServiceNow AI Platform

■ 対応手順
1. 自社で利用しているServiceNowのバージョンを確認してください。
2. ベンダーが公開した最新のセキュリティアドバイザリに基づき、修正パッチを適用してください。

■ 参考情報
- ServiceNow:August 2026 CVE Advisory Notification

対応優先度: 高
対応期限: 速やかに
Subject: [Security Alert] Critical Vulnerabilities in ServiceNow (CVE-2026-18885 et al.)

Dear IT Administration Team,

We are sharing critical security information regarding ServiceNow platforms.

■ Overview
Multiple critical vulnerabilities have been identified in ServiceNow's Now Platform and AI Platform. These include unauthenticated Remote Code Execution (RCE) via code injection (CVE-2026-18885), privilege escalation (CVE-2026-18886), and unauthenticated SQL injection (CVE-2026-74820), allowing unauthorized access to and modification of database content.

■ Scope
- ServiceNow Now Platform
- ServiceNow AI Platform

■ Action Required
1. Verify the current version of your ServiceNow instance.
2. Apply the latest security patches provided by the vendor immediately.

■ Reference
- ServiceNow: August 2026 CVE Advisory Notification

Priority: High
Deadline: Immediate