ServiceNow Fixes Five AI Platform Flaws Enabling SQL Injection, Data Theft and Privilege Escalation
Brief
ServiceNow released security updates for five vulnerabilities in its AI Platform, including two critical flaws that could let unauthenticated attackers execute SQL commands , extract sensitive instance data, and potentially escalate privileges.
The September 2026 advisory, tracked as KB3159623 and published on September 24, addresses CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
ServiceNow said it found no evidence that the vulnerabilities had been exploited maliciously in the wild.
ServiceNow Fixes Five AI Platform Flaws
The most severe issue is CVE-2026-13016, a critical SQL injection vulnerability identified in the ServiceNow AI Platform.
Under certain circumstances, the flaw could allow an unauthenticated attacker to execute arbitrary SQL statements against an affected instance’s underlying database.
