Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > ServiceNow Rushes Fixes for Five AI Platform Bugs After Two Are Rated Critical
ServiceNow Rushes Fixes for Five AI Platform Bugs After Two Are Rated Critical
Read Time:3 Minute, 16 Second

ServiceNow has shipped security updates addressing five vulnerabilities in its AI Platform, two of them rated critical, that together could allow an unauthenticated attacker to read, modify, or pull sensitive data straight out of an affected instance. The company says the flaws surfaced through a mix of internal testing, customer risk assessments, responsible disclosures, and its bug bounty program, and it has not found evidence any of them have been exploited in the wild — though the technical severity is high enough that patching quickly matters, especially for internet-facing instances.

The Five CVEs

The advisory covers CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860. The most serious of the group, CVE-2026-13016, is a SQL injection flaw in the ServiceNow AI Platform that could let an unauthenticated attacker run arbitrary SQL commands against the underlying database of an affected instance under certain conditions. In practice, that could mean an outsider reading, editing, or otherwise manipulating whatever data the instance stores — a significant risk given how many organizations route IT operations, security incidents, HR requests, asset inventories, and customer data through ServiceNow.

The second critical bug, CVE-2026-86860, is a missing-authorization vulnerability that could let an unauthenticated attacker pull instance data well beyond what the platform’s access controls are supposed to permit. ServiceNow warns that successful exploitation could also open the door to privilege escalation, handing an attacker access levels or permissions they were never meant to have.

Three More High-Severity Issues

The September 2026 advisory, tracked as KB3159623, also details three high-severity authorization and access-control weaknesses:

  • CVE-2026-86857 — an authorization bypass that could let an already-authenticated user view AI Platform data they shouldn’t have access to, potentially opening a path to further unintended access.
  • CVE-2026-86858 — an improper access control issue that, under the right conditions, could let an unauthenticated attacker create, modify, or delete instance data outside its intended permission boundaries, with knock-on risks to workflow integrity and record accuracy.
  • CVE-2026-86859 — a second authorization bypass, distinct from CVE-2026-86857, that could let an unauthenticated attacker reach AI Platform data that is supposed to be restricted.

Who’s Already Covered

Customers enrolled in ServiceNow’s August Patching Program have reportedly already received the relevant fixes automatically. Self-hosted customers, however, need to act on their own — ServiceNow is urging them to upgrade or apply the released patches immediately rather than waiting for a routine maintenance window.

The patched releases include Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 4a W32, and Australia Patch 2 Hot Fix 4b W32, along with additional remediated builds: Zurich Patch 10 Hot Fix 3b, Zurich Patch 11 Hot Fix 3, Australia Patch 4 Hot Fix 3, and Australia Patch 5.

What Administrators Should Do Now

Given the exposure a successful SQL injection or authorization bypass could create on a platform this central to enterprise operations, security teams should treat this as a priority patch rather than a routine one. Practical steps include:

  • Confirming the exact version and patch level of every self-hosted ServiceNow instance in the environment
  • Applying the listed hotfixes without delay, prioritizing instances reachable from the public internet
  • Reviewing administrative and service-account access on affected instances for anything that looks out of place
  • Monitoring logs for unusual database queries, unexpected data modifications, or authentication anomalies in the days following patching

No public proof-of-concept exploit code has surfaced for any of the five CVEs, and ServiceNow says its own investigation turned up no evidence of active exploitation. That window may not stay open for long once the patch details make the underlying weaknesses easier to reverse-engineer, which is exactly the pattern seen with past ServiceNow and enterprise SaaS vulnerabilities. Organizations that put off patching platforms like this tend to become the case study in the next round of disclosures.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on ServiceNow Rushes Fixes for Five AI Platform Bugs After Two Are Rated Critical, use the discussion on Forum.

>> forum community

Comments

Leave a Reply