ServiceNow security advisory (AV26-963)
Canada's Cyber Centre warns that multiple ServiceNow AI Platform versions need September 2026 security updates.
The Canadian Centre for Cyber Security issued advisory AV26-963 on September 25, 2026, for vulnerabilities in the ServiceNow AI Platform. Affected builds are earlier than Australia Patch 2 Hot Fix 4b W32, Australia Patch 4 Hot Fix 3, Australia Patch 5, Yokohama Patch 13 Hot Fix 5a, and several Zurich patch hotfixes. Administrators are urged to review ServiceNow advisories and apply updates. The notice lists no CVE identifiers and does not report exploitation.
- Advisory AV26-963 covers ServiceNow AI Platform flaws as of September 24, 2026.
- Australia, Yokohama, and Zurich families need the listed hotfixes.
- No CVE identifiers or active exploitation are stated.
Full article116 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-963
Date: September 25, 2026
As of September 24, 2026, ServiceNow is affected by vulnerabilities in the following product:
- ServiceNow AI Platform
- Versions prior to Australia Patch 2 Hot Fix 4b W32
- Versions prior to Australia Patch 4 Hot Fix 3
- Versions prior to Australia Patch 5
- Versions prior to Yokohama Patch 13 Hot Fix 5a
- Versions prior to Zurich Patch 10 Hot Fix 3b
- Versions prior to Zurich Patch 10 Hot Fix 4a W32
- Versions prior to Zurich Patch 11 Hot Fix 3
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/servicenow-security-advisory-av26-963