Skip to main content
cybersecurity

ServiceNow Patches Five AI Platform Vulnerabilities, Including Two Critical Flaws

ServiceNow has addressed five AI Platform vulnerabilities, including two critical flaws involving SQL injection and missing authorization. Canada's Cyber Centre urges administrators to check affected versions and apply the available security updates.

Xcademia Team

Xcademia Research Team

Sep 26, 20264 min read2 views
Share:
ServiceNow Patches Five AI Platform Vulnerabilities, Including Two Critical Flaws

ServiceNow has released security updates addressing five vulnerabilities in its AI Platform, including two critical and three high-severity issues.

The Canadian Centre for Cyber Security published advisory AV26-963 on September 25, 2026, identifying affected ServiceNow AI Platform releases and encouraging users and administrators to apply the necessary updates.

ServiceNow's September 2026 CVE notification identifies the five vulnerabilities as CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.

The issues involve authorization bypass, improper access control, SQL injection, and missing authorization.

ServiceNow says it remediated all five vulnerabilities and did not identify evidence of malicious exploitation related to them.


Two Critical Vulnerabilities Affect Database and Access Security

ServiceNow assessed the five vulnerabilities using the CVSS v4.0 calculator.

CVE

Severity

Vulnerability

CVE-2026-86857

High

Authorization bypass

CVE-2026-86858

High

Improper access control

CVE-2026-13016

Critical

SQL injection

CVE-2026-86859

High

Authorization bypass

CVE-2026-86860

Critical

Missing authorization

CVE-2026-13016: SQL Injection

ServiceNow says this critical vulnerability could allow an unauthenticated user, under certain circumstances, to execute arbitrary SQL statements against the instance's underlying database.

Potential consequences include accessing or modifying instance data beyond what was intended.

CVE-2026-86860: Missing Authorization

This critical vulnerability could allow an unauthenticated user to extract instance data beyond the intended permissions and potentially result in privilege escalation.

Three High-Severity Vulnerabilities

  • CVE-2026-86857: An authenticated user could access data they would not otherwise be authorized to view.

  • CVE-2026-86858: An unauthenticated user could, in certain circumstances, create, modify, or delete instance data beyond intended permissions.

  • CVE-2026-86859: An unauthenticated user could potentially access data outside their permitted scope.

ServiceNow says these issues were remediated independently.


info-1


Affected ServiceNow AI Platform Versions

The Canadian Cyber Centre's advisory identifies the following affected release ranges as of September 24, 2026.

Release

Affected Versions

Australia

Before Patch 2 Hot Fix 4b W32

Australia

Before Patch 4 Hot Fix 3

Australia

Before Patch 5

Yokohama

Before Patch 13 Hot Fix 5a

Zurich

Before Patch 10 Hot Fix 3b

Zurich

Before Patch 10 Hot Fix 4a W32

Zurich

Before Patch 11 Hot Fix 3

Administrators should compare their current release and hotfix level against the affected versions and the corrected releases listed by ServiceNow.


Updated Versions Containing the Fixes

ServiceNow says customers participating in its August Patching Program received the appropriate updates.

The company lists the following releases as containing remediations for all five CVEs.

Release

Updated Version

Yokohama

Patch 13 Hot Fix 5a

Zurich

Patch 10 Hot Fix 4a W32

Australia

Patch 2 Hot Fix 4b W32

Zurich

Patch 10 Hot Fix 3b

Zurich

Patch 11 Hot Fix 3

Australia

Patch 4 Hot Fix 3

Australia

Patch 5


What Administrators Should Do

ServiceNow recommends that self-hosted customers promptly apply the appropriate updates or upgrade to a patched release if they have not already done so.

Administrators should:

  1. Identify the ServiceNow AI Platform release currently deployed.

  2. Check the patch and hotfix level against the affected versions.

  3. Apply the appropriate security update or upgrade to a corrected release.

  4. Verify that the instance is running a version containing the remediations.

  5. Review the official advisory resources for additional instructions.

The supplied advisory does not specify a separate workaround for customers who cannot immediately apply the updates.


info-2

ServiceNow Reports No Evidence of Malicious Exploitation

According to ServiceNow, the vulnerabilities were identified through internal security testing, customer security assessments, and reports submitted through responsible disclosure and bug bounty programs.

The company stated that it had remediated each issue independently and had not identified evidence of malicious exploitation related to the five vulnerabilities.

This is ServiceNow's reported assessment and does not establish that every customer environment has been independently evaluated.


Why the Advisory Matters

The vulnerabilities affect different security controls, but their potential consequences center on access to sensitive information, data integrity, and authorization boundaries.

For enterprise administrators, the advisory highlights the importance of maintaining supported application versions and applying security updates that address access-control and database-related flaws.

The distinction between severity and exploitation is also important: ServiceNow rated two vulnerabilities critical and three high while reporting no evidence of malicious exploitation related to these issues.

Conclusion

ServiceNow has addressed five vulnerabilities affecting its AI Platform, including critical flaws involving SQL injection and missing authorization.

The Canadian Centre for Cyber Security's advisory AV26-963 identifies affected versions across the Australia, Yokohama, and Zurich release families.

ServiceNow recommends that self-hosted customers promptly apply the appropriate updates or upgrade to a patched release. The company also reported that it had not identified evidence of malicious exploitation related to the five vulnerabilities.

For administrators, the immediate priority is to verify the deployed version and ensure that the instance includes the available security fixes.

#Cybersecurity#ServiceNow#SecurityAdvisory#VulnerabilityManagement#SQLInjection#AccessControl#PatchManagement#EnterpriseSecurity

About the Author

X
Xcademia Team
Xcademia Research Team
Share:
Learn to stop attacks like this oneCybersecurity Engineer Bootcamp: live cohorts enrolling now, with optional Career+ support.