Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: graphql (2 articles)Clear

Three critical ServiceNow flaws let unauthenticated attackers run code and SQL

ServiceNow patched four flaws in its widely used AI Platform, three of them scored 10.0 and exploitable by an unauthenticated attacker with no user interaction. The first, CVE-2026-18885, is a code injection in the GraphQL Composite Data API that allows arbitrary code execution and access to instance data. The second, CVE-2026-18886, is an access-control flaw in the configuration image-upload processor that lets an attacker create or modify data and escalate privileges. The third, CVE-2026-74820, is a SQL injection allowing arbitrary queries against the instance database. ServiceNow fixed hosted instances itself, but self-managed customers must apply the updates. No exploitation of these three has been reported yet.

Check
Self-hosted ServiceNow customers should apply the platform updates immediately, since ServiceNow only patched its own hosted instances, and confirm production instances are on a fixed version.
Affected
Organizations running the ServiceNow AI Platform, especially self-managed instances (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820); unauthenticated attackers can execute code, manipulate data, escalate privileges, or run arbitrary SQL with no interaction.
Fix
Patch self-hosted instances now, restrict network access to ServiceNow where possible, review logs for suspicious GraphQL requests, unexpected configuration or data changes, and anomalous database queries, and prioritize internet-reachable instances.

Critical GitLab flaw lets unauthenticated attackers delete public projects and data

GitLab shipped an out-of-band critical patch for a flaw that lets an unauthenticated attacker remotely modify or delete public projects and user data through a GraphQL directive. Tracked as CVE-2026-19478 and scored 9.4, it affects self-managed Community and Enterprise installations; GitLab.com and Dedicated are already fixed. The company released it outside its normal twice-monthly schedule, and the fixed versions are 19.2.4, 19.1.6, 19.0.8, and 18.11.11, with the 18.2 through 18.10 branches left in the affected range and needing an upgrade. A second, lower-severity GraphQL flaw involving cross-site request forgery was fixed in the same release. GitLab reports no known exploitation yet.

Check
Upgrade self-managed GitLab to a fixed release immediately, and if you run a version between 18.2 and 18.10, plan an upgrade since those branches did not receive a backported fix.
Affected
Organizations running self-managed GitLab Community or Enterprise Edition (CVE-2026-19478); an unauthenticated attacker can remotely modify or delete public projects and user data through a GraphQL directive.
Fix
Apply the out-of-band patch now, prioritize internet-reachable instances, review logs for unexpected GraphQL activity and project or user changes, and restore any affected projects from backups if tampering is found.