ServiceNow Fixes Critical Flaws in AI Platform Including Three CVSS 10.0 Vulnerabilities

ServiceNow has disclosed and patched four security vulnerabilities affecting its AI Platform, with three critical flaws scoring 10.0 on the CVSS scale. These flaws could potentially be exploited by unauthenticated attackers under certain circumstances, raising risks for customers using hosted, partner, or self-hosted deployments.
What happened
ServiceNow identified four security vulnerabilities in its AI Platform, three of which hold the maximum CVSS score of 10.0. These critical flaws allow remote unauthenticated attackers to possibly execute code or perform SQL injection attacks under specific conditions. The company has already deployed patches to all hosted instances and made the updates available to its partners and self-hosted customers to mitigate these risks.
Why it matters
Given the severity and exploitability of these vulnerabilities without prior authentication, organizations using ServiceNow’s AI Platform face potential exposure to remote code execution and data manipulation attacks. This could lead to compromised data integrity, unauthorized access, or disruption of services, especially if patches are not promptly applied. The release highlights the risks inherent in complex AI-integrated platforms in enterprise environments.
What security teams should do
Organizations using ServiceNow AI Platform should immediately verify that their instances have received the latest security patches. For self-hosted environments and partner-managed deployments, applying the provided updates quickly is critical to prevent exploitation. Security teams should also monitor logs for unusual activities indicative of exploitation attempts and review access controls to minimize risk exposure.
Key technical details
The security update addresses four vulnerabilities, with three scoring a CVSS of 10.0, indicating critical severity. These flaws potentially allow unauthenticated attackers to execute arbitrary code and perform SQL injection attacks via the AI Platform’s exposed interfaces under specific circumstances. ServiceNow’s patches close these attack vectors across hosted and self-managed environments, though details on the exact nature and mechanics of each vulnerability have not been publicly disclosed.
Affected organizations/products
The vulnerabilities affect the ServiceNow AI Platform across hosted instances, partner-managed, and self-hosted deployments. While hosted instances have been patched by ServiceNow, organizations running self-hosted environments must apply the updates provided by the vendor. This broad scope underscores the need for all users of this platform to take action.
Source attribution
https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html