ServiceNow patches five AI Platform security flaws
ServiceNow fixed five AI Platform flaws, including critical SQL injection, and reports no known exploitation.
ServiceNow disclosed five AI Platform vulnerabilities in advisory KB3159623, dated September 24, 2026, and told self-hosted customers to install September 2026 fixed releases. Critical CVE-2026-13016 is unauthenticated SQL injection that can execute arbitrary SQL and access or alter instance data, while critical CVE-2026-86860 is missing authorization that can expose data and enable privilege escalation. High-severity CVE-2026-86857, CVE-2026-86858, and CVE-2026-86859 are authorization and access-control issues; one account says those three can be authenticated or unauthenticated. ServiceNow reports no evidence of exploitation. Self-hosted hotfixes named in the coverage include Yokohama, Zurich, and Australia releases, and one report says August program customers already have fixes. Canada’s AV26-963 notice of September 25, 2026, lists affected builds earlier than Australia Patch 2 Hot Fix 4b W32, Australia Patch 4 Hot Fix 3, Australia Patch 5, Yokohama Patch 13 Hot Fix 5a, and several Zurich hotfixes, but names no CVEs and does not address exploitation. GBHackers’ bullet list calls both critical flaws unauthenticated, while the detailed write-ups clearly apply that label only to the SQL injection.
- ServiceNow advisory KB3159623, dated September 24, 2026, covers five AI Platform vulnerabilities found through internal testing, customer assessments, and its bug bounty.
- Critical CVE-2026-13016 is unauthenticated SQL injection that can run arbitrary SQL and read or modify instance data.
- Critical CVE-2026-86860 is a missing-authorization flaw that can extract data and support privilege escalation.
- High-severity CVE-2026-86857, CVE-2026-86858, and CVE-2026-86859 are authorization or access-control flaws; one report says they can allow authenticated or unauthenticated bypass.
- ServiceNow says it has no evidence of exploitation and urges self-hosted customers to apply September 2026 fixes, including Yokohama, Zurich, and Australia hotfixes; one report says August program customers already have fixes.
- Canada’s Cyber Centre advisory AV26-963 (September 25, 2026) flags builds earlier than Australia Patch 2 Hot Fix 4b W32, Australia Patch 4 Hot Fix 3, Australia Patch 5, Yokohama Patch 13 Hot Fix 5a, and several Zurich patch hotfixes, but…
Coverage timelineoldest first · each row is one article
- · 1d agoServiceNow Security Flaws Allow Attackers to Execute SQL and Modify Instance Data
GBHackers· 72
ServiceNow patched five AI Platform flaws, including critical unauthenticated SQL injection and missing authorization.
- · 1d agoCritical ServiceNow Vulnerabilities Let Attackers Bypass Authorization – Update Now!
Cyber Security News· 76
ServiceNow patched five AI Platform flaws, including critical unauthenticated SQL injection, with no known exploitation.
- · 1d agoServiceNow security advisory (AV26-963)
Canadian Centre for Cyber Security· 34
Vulnerabilities in this storyAll →
- CVE-2026-130169.3—Unauthenticated SQL Injection in ServiceNow AI Platform (CVSS 9.3)published · ServiceNow AI Platform (ServiceNow instance/platform)+4 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-13016+4 related CVEs | Unauthenticated SQL Injection in ServiceNow AI Platform (CVSS 9.3) |