ServiceNow fixes two critical unauthenticated flaws in its AI Platform: self-hosted instances need the patch now
EditorialBy TrustList Editorial
ServiceNow disclosed five vulnerabilities in its AI Platform on 24 September 2026, two of them critical (CVE-2026-13016 and CVE-2026-86860, CVSS 9.3) and exploitable without authentication. Belgium’s CCB says patch immediately.
- Cybersecurity
- Cybersecurity Software
- Help Desk Software
- IT Risk Management
About ServiceNow fixes two critical unauthenticated flaws in its AI Platform: self-hosted instances need the patch now
ServiceNow fixes two critical unauthenticated flaws in its AI Platform: self-hosted instances need the patch now
24 September 2026 — ServiceNow published a security advisory (KB3159623) on 24 September 2026 covering five vulnerabilities in the ServiceNow AI Platform, the platform under its IT service management, HR, customer-service and workflow products. Two are rated critical. The Centre for Cybersecurity Belgium (CCB) followed on 25 September with a warning headed "patch immediately", and Italy's national cyber agency issued its own notice the same day. ServiceNow said it had seen no evidence of exploitation.
The vulnerabilities
- CVE-2026-13016 (CVSS 9.3): SQL injection. Under certain circumstances an unauthenticated remote attacker could run arbitrary SQL statements against the instance database.
- CVE-2026-86860 (CVSS 9.3): missing authorisation. An unauthenticated remote attacker could extract instance data beyond the intended authorisation boundary, potentially leading to privilege escalation.
- CVE-2026-86857 (8.4), CVE-2026-86858 (8.7) and CVE-2026-86859 (8.7): high-severity issues fixed in the same release.
The two critical flaws need no credentials and no user interaction, which is why the CCB rates them as urgent.
Who is affected
ServiceNow patches the instances it hosts. Customers who run self-hosted instances, and customers on hosted instances that have deferred upgrades, must check their release. According to the advisory, customers enrolled in ServiceNow's August patching programme already have the fix; the fixed levels listed include Yokohama Patch 13 HF5a, Zurich Patch 10 HF4a W32 and later Zurich patches, and Australia Patch 2 HF4b W32 and later Australia patches.
What to do
- Confirm the family, patch and hotfix level of every ServiceNow instance you run, including sub-production instances that hold copies of real data.
- Apply the fixed patch listed in KB3159623 for your family, after testing, with the highest priority.
- Review database and access logs for unusual queries or data exports, since patching does not undo any earlier compromise.
- If a partner or managed-service provider runs your instance, ask for written confirmation of the patch level and the date it was applied.
Sources
Categories & features
- Cybersecurity
- Cybersecurity Software
- Help Desk Software
- IT Risk Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.