September 8, 2026
By esentry Team

Critical ServiceNow Flaws Expose AI Platform to Remote Code and Data Attacks

ServiceNow has released security updates for three critical vulnerabilities affecting its AI Platform. The flaws could allow an unauthenticated attacker to execute code, access or modify sensitive data, escalate privileges, or interact directly with the underlying database.

All three vulnerabilities received the maximum CVSS score of 10.0 and can be exploited remotely without requiring user interaction.

The vulnerabilities affect the GraphQL Composite Data API, system configuration image upload processor and dynamic schema functionality respectively.

Affected Versions

ServiceNow identified affected releases across:

  • Xanadu
  • Yokohama
  • Zurich
  • Australia

ServiceNow has released fixes for these versions, with specific patch and hotfix levels provided in its August 2026 advisory.

Impact

Successful exploitation could allow an attacker to:

  • Execute arbitrary code.
  • Access or modify ServiceNow instance data.
  • Escalate privileges.
  • Execute unauthorized SQL queries.
  • Compromise the confidentiality, integrity, and availability of affected systems.

Because ServiceNow is commonly used for IT operations, HR, finance, customer service, and business workflows, exploitation could expose sensitive enterprise information and business processes.

Recommendations

Organizations using ServiceNow should:

  • Apply the latest ServiceNow security patches immediately.
  • Prioritize remediation of the three CVSS 10.0 vulnerabilities.
  • Identify whether any self-hosted ServiceNow instances are running affected versions.
  • Review ServiceNow logs for unusual API requests, authentication activity, data modification, and administrative actions.
  • Monitor for unexpected database queries or changes to sensitive records.
  • Review privileged accounts and permissions for unauthorized changes.
  • Conduct a follow-up vulnerability assessment after patching.

ServiceNow has already deployed fixes to its hosted instances and provided hotfixes for self-hosted environments.

The combination of remote exploitation, no authentication requirement, low attack complexity and potential for arbitrary code execution and data manipulation makes these vulnerabilities a high-priority remediation item.