Critical ServiceNow Flaws Let Attackers Execute Code and Access Data
Brief
ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access sensitive instance data , modify records, or escalate privileges.
The company published its August 2026 CVE advisory on August 27, confirming that the issues were discovered through its internal security research and responsible disclosure programs.
ServiceNow said each vulnerability was remediated independently and urged self-hosted customers to promptly apply the available updates or upgrade to a patched release.
ServiceNow Fixes Critical Flaws
Three of the flaws affect the ServiceNow AI platform.
