Security & Risk5 minNewsroom

ServiceNow Fixes Maximum CVSS Score Vulnerabilities in AI Platform Used by G7 Companies

Centro de operações de TI corporativo com painéis de monitoramento e alerta vermelho crítico na tela, representando vulnerabilidades críticas na plataforma ServiceNow

ServiceNow has released patches for four critical vulnerabilities in the Now Platform and AI Platform, two of which have a CVSS score of 10.0. These vulnerabilities allow code execution and SQL injection by unauthenticated attackers without user interaction.

Critical Failures in Mission-Critical Platform


On August 27, 2026, ServiceNow announced four critical vulnerabilities in the Now Platform and AI Platform, including two with a CVSS score of 10.0, the highest rating on the standard severity scale. These vulnerabilities allow unauthenticated attackers to execute arbitrary code and perform SQL injections on platform instances without the need for credentials or user interaction. ServiceNow stated that no active exploitation had been identified by the time patches were released.


The platform is among the most widely adopted in the global enterprise market for IT service management (ITSM), IT operations management (ITOM), and workflow automation. Its reach spans from major banks and insurance companies to national governments and regulated industries, making the vulnerabilities relevant to thousands of organizations across multiple sectors.


Type of Vulnerability and Attack Surface


The two most severe vulnerabilities were identified in the AI Platform, the set of artificial intelligence tools integrated into the Now Platform throughout 2025 and 2026. One resides in the API GraphQL layer of the platform and facilitates code injection resulting in remote execution and access to or modification of instance data. The second vulnerability, also of maximum severity, involves code injection in another component of the AI Platform.


Exposed GraphQL APIs in enterprise SaaS platforms represent a high attack surface: frequently accessible via the internet, they connect multiple internal systems and carry data from numerous tenants. A successful unauthenticated attack on this layer could expose automation configurations, customer data, and integration credentials of third-party systems connected to the instance.


Two additional vulnerabilities of lower severity were also addressed in the same patch cycle. No public proof of concept had been released by the time this article went to press.


Available Patches and Version Management


ServiceNow automatically distributes patches to customers enrolled in the Patching Program. Affected versions span multiple release lines, including Xanadu, Yokohama, Zurich, and Australia. Organizations maintaining instances on unmanaged versions or with delayed update cycles need to apply patches manually and as a top priority.


Delaying updates is a known friction in highly customized ServiceNow environments. Companies that freeze versions to stabilize configurations remain exposed during times when response speed is critical. This week’s patch release cycle placed direct pressure on IT teams, which must justify update backlogs in front of increasingly attentive risk advisory boards and committees regarding incidents in widely adopted software.


Global Reading: U.S., Europe, and Consultancy Obligations


In the United States, where ServiceNow is headquartered and where the largest volume of enterprise deployments is concentrated, federal organizations subject to FISMA must document risk assessments and corrective action even in the absence of confirmed exploitation. The CISA (Cybersecurity and Infrastructure Security Agency) may add the vulnerability to its catalog of Known Exploited Vulnerabilities (KEV) if active exploitation is detected, requiring U.S. federal agencies to remediate within short timeframes, typically 15 days.


In Europe, the NIS2 imposes an obligation on essential and important entities to implement cybersecurity risk management measures, which include applying critical patches within timelines commensurate with the level of risk. With a CVSS of 10.0, the vulnerabilities in ServiceNow fall into the category that requires immediate response. Major banks in Germany (Deutsche Bank, Commerzbank), insurers in France (AXA, Allianz), and telecommunications operators in the UK running ServiceNow as their central ITSM platform must demonstrate compliance with the vulnerability management obligations of NIS2 or the UK Cyber Resilience Act under discussion.


For IT consultancies and system integrators that build and maintain ServiceNow instances (Accenture, Deloitte, KPMG, and IBM Consulting are among the platform’s leading global partners), this alert implies immediate activation of version verification protocols across their managed client base. Managed services contracts on ServiceNow typically include SLA clauses for critical patches, and a successful exploitation in a managed environment exposes the integrator to direct contractual liability.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk