ServiceNow has disclosed five security flaws in the ServiceNow AI Platform, the system many large organisations use to run IT service desks and internal workflows. Two of them are rated critical, and four of the five can be reached by someone with no account on the instance. It is the second batch of serious ServiceNow bugs this month, after the four CVSS 10.0 flaws disclosed in early September.
The flaws are covered by ServiceNow's advisory KB3159623, and their CVE records were published on September 24. ServiceNow says it has already deployed the fix to the instances it hosts and has provided the update to partners and self-hosted customers. It says it is not currently aware of malicious exploitation. Peru's national digital security centre (CNSD) flagged the batch in its integrated security alert 184-2026.
Two critical bugs need no login
The scores below are the CVSS 4.0 ratings ServiceNow's own security team assigned. ServiceNow's descriptions say what each flaw could let an attacker do, but not how it is triggered, and the published records carry no exploitation detail.
- CVE-2026-13016 (CVSS 9.3, critical): a SQL injection flaw, meaning attacker input can end up executed as a database command. ServiceNow says it could let an unauthenticated user, in certain circumstances, run arbitrary SQL statements against the instance's underlying database and read or modify data beyond what was intended.
- CVE-2026-86860 (CVSS 9.3, critical): a missing authorization check that could let an unauthenticated user, in certain circumstances, extract instance data beyond what was intended, resulting in privilege escalation.
- CVE-2026-86858 (CVSS 8.7, high): an improper access control issue that could let an unauthenticated user, in certain circumstances, create, modify or delete instance data.
- CVE-2026-86859 (CVSS 8.7, high): an authorization bypass that could let an unauthenticated user access AI Platform data they are not entitled to.
- CVE-2026-86857 (CVSS 8.4, high): an authorization bypass that requires an authenticated user, who could then reach data beyond their entitlement.
Hosted customers are covered, self-hosted are not yet
ServiceNow's record for CVE-2026-86858 states that the hosted-instance update was deployed in August 2026, so the fixes were in place on ServiceNow's cloud before the flaws were made public. Self-hosted customers and anyone running an instance through a partner are the exposed group: the fix exists, but it only protects them once it is applied. According to CNSD's summary of the advisory, ServiceNow found the issues through internal testing, customer security assessments, responsible disclosure reports and its bug bounty programme.
Apply the KB3159623 update or move to a patched release
ServiceNow recommends customers promptly apply the appropriate updates or upgrade to a patched release. The advisory, not the CVE records, lists which releases carry the fix, so self-hosted administrators should check their version against KB3159623 directly. Partner-hosted customers should confirm with their provider that the update is installed rather than assume it arrived with ServiceNow's own cloud rollout.
Nothing here is known to be under attack. But ServiceNow instances hold exactly the data an intruder wants, from employee records to change tickets that map an organisation's infrastructure, and two unauthenticated critical bugs in one month is a strong argument for treating a self-hosted instance's patch cycle with the same urgency as an internet-facing VPN.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.