MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-25 · via SQ Magazine

ServiceNow Releases Fixes for Five AI Platform Vulnerabilities

Image via SQ Magazine
Image via SQ Magazine

ServiceNow has addressed five security bugs in its AI Platform as part of a September 2026 advisory, with four requiring no login to exploit. The most severe, CVE-2026-13016, is a critical SQL injection that could let an unauthenticated attacker run arbitrary database commands, while CVE-2026-86860 is a critical missing-authorization flaw. The company says it has not seen active exploitation and has patched hosted instances, but self-hosted customers and partners must install specified fixed builds.

Expanded Detail

ServiceNow’s September 2026 advisory covers five AI Platform bugs. Four can be reached without signing in. The two critical issues are CVE-2026-13016, an SQL injection that may allow arbitrary database commands, and CVE-2026-86860, a missing-authorization flaw that may expose instance data or enable privilege escalation. Three high-severity bugs involve access-control or authorization bypasses; one requires login.

The vendor says hosted instances are already remediated and reports no known malicious exploitation. Self-hosted customers and partners must apply fixed builds, including specified Yokohama, Zurich, and Australia patches. Public records remain incomplete: a GitHub advisory entry for CVE-2026-13016 lists affected and patched versions as unknown and is unreviewed.

Context

ServiceNow underpins IT operations, incident response, employee requests, asset records, and customer data at many organizations. If unpatched self-hosted instances were exploited, attackers could potentially read or alter records, possibly misleading responders or disrupting workflows. Employees, customers, and partners whose data sits in those systems may face privacy or operational harms. The vendor’s hosted fix reduces one exposure path, but self-hosted operators’ patch timing could shape how broadly any risk materializes.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at SQ Magazine →
Related stories
September 22 OT Security and Regulatory Update · Cybersecurity
Industrial Cybersecurity Briefing for September 25 · Cybersecurity
Roundcube Webmail SQL Injection Bug Exploited Before Patch · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “ServiceNow Security Alert: Patch These Critical Flaws.” Browse more stories.