ServiceNow Patches Three CVSS 10.0 Flaws in AI Platform
ServiceNow patches three CVSS 10.0 AI Platform flaws. Self-hosted customers must update now; hosted instances were auto-patched August 28.

Three CVSS 10.0 vulnerabilities. One advisory. Patches are out.
ServiceNow released security patches on August 28, 2026 for four flaws in its AI Platform. Three carry a maximum CVSS 10.0 score. The attack surface is unauthenticated: no credentials required to reach the vulnerability. Per BleepingComputer’s coverage, the confirmed vulnerability classes are code injection, SQL injection, and privilege escalation.
CVE identifiers have not been published as of this writing.
Who is exposed
Self-hosted ServiceNow AI Platform deployments that have not applied the update. Hosted instances received an automatic patch on August 28. If you run a self-hosted deployment, the patch is available now. No delay is justified.
CVSS 10.0 is the maximum possible score. Three separate flaws at that rating in a single advisory is unusual. The scores indicate full theoretical impact on confidentiality, integrity, and availability, reachable by an unauthenticated attacker.
What to do
- Self-hosted: Apply the ServiceNow AI Platform security update immediately.
- Hosted: Verify your instance reflects the August 28 patched build through the ServiceNow support portal or your Customer Success Manager.
- Review AI Platform audit logs for anomalous query patterns or unexpected privilege changes starting from August 27.
- Monitor the ServiceNow security advisory portal for CVE identifiers once assigned.
Context
This is the second significant vulnerability cluster in the ServiceNow AI Platform this year. July 2026 brought CVE-2026-6875, a ServiceNow AI Platform RCE that reached active exploitation. The four new flaws are a distinct set, not a variant of that case.
ServiceNow deployments commonly hold high-value enterprise data: IT service records, HR workflows, procurement data, and in many organizations, privileged access management integrations. A foothold in an unpatched instance is a meaningful acquisition target. Exploitation has not been confirmed at publication time. Unconfirmed: treat accordingly, but prioritize patching ahead of the weekend.
Additional technical coverage from The Hacker News.
Found this useful? Share it.
