B
今週中
ServiceNowの「Now Platform」および「ServiceNow AI Platform」において、複数の深刻な脆弱性
📌 一言でいうと
ServiceNowの「Now Platform」および「ServiceNow AI Platform」において、複数の深刻な脆弱性が公開されました。認証なしで任意のコード実行が可能なコードインジェクション(CVE-2026-18885)や、権限昇格につながるアクセス制御不備(CVE-2026-18886)、および任意のSQL実行が可能なSQLインジェクション(CVE-2026-74820)が含まれています。ベンダーより修正版が公開されており、迅速な適用が推奨されます。
🔍該当判定
- 社内で「ServiceNow」を導入して利用している
- 「Now Platform」を業務管理やITサービス管理に利用している
- 「ServiceNow AI Platform」を導入し、AI機能を活用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
ServiceNowが提供する最新のセキュリティパッチを適用し、修正版へアップデートしてください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】ServiceNow 複数クリティカル脆弱性 (CVE-2026-18885 他) 対応について
お疲れさまです。ServiceNow製品の深刻な脆弱性に関する情報共有です。
■ 概要
ServiceNowのプラットフォームにおいて、認証なしで任意のコード実行やSQL実行、権限昇格が可能な複数のクリティカルな脆弱性が判明しました。特にCVE-2026-18885およびCVE-2026-74820は、外部から認証なしにデータ操作が行われるリスクがあり、極めて危険です。
■ 影響範囲
- ServiceNow Now Platform
- ServiceNow AI Platform
■ 対応手順
1. 自社で利用しているServiceNowのバージョンを確認してください。
2. ベンダーが公開した最新のセキュリティアドバイザリに基づき、修正パッチを適用してください。
■ 参考情報
- ServiceNow:August 2026 CVE Advisory Notification
対応優先度: 高
対応期限: 速やかに
お疲れさまです。ServiceNow製品の深刻な脆弱性に関する情報共有です。
■ 概要
ServiceNowのプラットフォームにおいて、認証なしで任意のコード実行やSQL実行、権限昇格が可能な複数のクリティカルな脆弱性が判明しました。特にCVE-2026-18885およびCVE-2026-74820は、外部から認証なしにデータ操作が行われるリスクがあり、極めて危険です。
■ 影響範囲
- ServiceNow Now Platform
- ServiceNow AI Platform
■ 対応手順
1. 自社で利用しているServiceNowのバージョンを確認してください。
2. ベンダーが公開した最新のセキュリティアドバイザリに基づき、修正パッチを適用してください。
■ 参考情報
- ServiceNow:August 2026 CVE Advisory Notification
対応優先度: 高
対応期限: 速やかに
Subject: [Security Alert] Critical Vulnerabilities in ServiceNow (CVE-2026-18885 et al.)
Dear IT Administration Team,
We are sharing critical security information regarding ServiceNow platforms.
■ Overview
Multiple critical vulnerabilities have been identified in ServiceNow's Now Platform and AI Platform. These include unauthenticated Remote Code Execution (RCE) via code injection (CVE-2026-18885), privilege escalation (CVE-2026-18886), and unauthenticated SQL injection (CVE-2026-74820), allowing unauthorized access to and modification of database content.
■ Scope
- ServiceNow Now Platform
- ServiceNow AI Platform
■ Action Required
1. Verify the current version of your ServiceNow instance.
2. Apply the latest security patches provided by the vendor immediately.
■ Reference
- ServiceNow: August 2026 CVE Advisory Notification
Priority: High
Deadline: Immediate
Dear IT Administration Team,
We are sharing critical security information regarding ServiceNow platforms.
■ Overview
Multiple critical vulnerabilities have been identified in ServiceNow's Now Platform and AI Platform. These include unauthenticated Remote Code Execution (RCE) via code injection (CVE-2026-18885), privilege escalation (CVE-2026-18886), and unauthenticated SQL injection (CVE-2026-74820), allowing unauthorized access to and modification of database content.
■ Scope
- ServiceNow Now Platform
- ServiceNow AI Platform
■ Action Required
1. Verify the current version of your ServiceNow instance.
2. Apply the latest security patches provided by the vendor immediately.
■ Reference
- ServiceNow: August 2026 CVE Advisory Notification
Priority: High
Deadline: Immediate