TL;DR
On September 24, 2026, developers released security patches to address five ServiceNow vulnerabilities within the AI Platform. These flaws include a critical unauthenticated SQL injection issue and multiple authorization bypasses. System administrators must apply the latest patches to Yokohama, Zurich, and Australia release branches immediately.
- Total: 5 CVEs
- Severity: 2 Critical · 3 High
- Actively exploited: None confirmed
- Highest severity: 9.3 (Critical · CVSSv4) — CVE-2026-13016
- Action: Apply the latest security updates now
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-13016 | 9.3 | Unauthenticated SQL Injection in | Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 3b, Zurich Patch 10 Hot Fix 4a W32 (+4) | Not exploited |
| CVE-2026-86860 | 9.3 | Unauthenticated Sensitive Data Disclosure in | Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 3b, Zurich Patch 10 Hot Fix 4a W32 (+4) | Not exploited |
| CVE-2026-86858 | 8.7 | Unauthenticated Privilege Escalation via GraphQL in | Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 3b, Zurich Patch 10 Hot Fix 4a W32 (+4) | Not exploited |
| CVE-2026-86859 | 8.7 | Unauthenticated Arbitrary Record Disclosure in | Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 3b, Zurich Patch 10 Hot Fix 4a W32 (+4) | Not exploited |
| CVE-2026-86857 | 8.4 | Authorization Bypass in | Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 3b, Zurich Patch 10 Hot Fix 4a W32 (+4) | Not exploited |
Why It Matters
Industry telemetry estimates that over 80 percent of Fortune 500 enterprises deploy ServiceNow for IT service management. Consequently, severe defects in this central data hub expose highly sensitive corporate information. The most dangerous flaw, CVE-2026-13016, carries a CVSS score of 9.3. Another critical missing authorization flaw, CVE-2026-86860, also carries a 9.3 severity rating.
Fortunately, the vendor discovered these ServiceNow vulnerabilities during internal assessments and bug bounty programs. In the official advisory, the company stated, “ServiceNow did not identify evidence of malicious exploitation related to these issues.” Furthermore, researchers have not published any public proof-of-concept exploit code. However, unpatched self-hosted instances remain at risk of data extraction and privilege escalation.
How The Attack Works
The security issues target the ServiceNow AI Platform subsystem. For the SQL injection defect, an unauthenticated attacker sends malicious database queries through vulnerable input fields. The application fails to sanitize this input. This allows the attacker to execute arbitrary SQL commands directly against the underlying database.
Other flaws involve improper access control and missing authorization checks. For instance, CVE-2026-86860 enables unauthenticated users to extract instance data beyond their intended scope. This action results in direct privilege escalation. Additionally, CVE-2026-86857 allows authenticated users to access restricted data sets through broken authorization boundaries.
Affected Versions
These defects affect multiple versions of the ServiceNow AI Platform. Vulnerable branches include the Yokohama, Zurich, and Australia releases prior to the September 2026 patch cycle.
Patch Or Mitigation Steps
Administrators running self-hosted environments must install the latest updates without delay. The vendor already updated cloud-hosted instances automatically. To secure your local deployment, apply the ServiceNow security update for your specific release branch. For example, Yokohama users should install Patch 13 Hot Fix 5a, while Zurich users require Patch 10 Hot Fix 3b. Applying these hotfixes eliminates the risk of unauthorized database access.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!