Security · September 27, 2026

Also published in العربية, Polski, Français, Norsk, Deutsch

Multiple vulnerabilities discovered in ServiceNow AI Platform

a computer screen with a bunch of code on it
Chris Ried / Unsplash

Multiple vulnerabilities have been identified in the ServiceNow AI Platform, with several classified as critical. ServiceNow is urging users to update their systems following the security advisory published on September 24, 2026.

The advisory revealed five vulnerabilities based on the Common Vulnerabilities and Exposures (CVE) system, identified through internal security testing, collaborative reporting, and a bug bounty program.

The vulnerability identified as CVE-2026-13016 allows for SQL injection exploitation without authentication in certain environments, potentially enabling unauthorized access and manipulation of databases within instances.

Another vulnerability, CVE-2026-86860, stems from improper authorization handling, which could allow data extraction from instances without authentication and enable privilege escalation.

Both vulnerabilities have been assigned a base score of 9.3 on the Common Vulnerability Scoring System version 4.0 (CVSSv4.0), indicating a critical severity rating. ServiceNow's proactive measures aim to ensure the security of its user base against these significant threats.