← Back to Feed
ServiceNow warns of three max severity security vulnerabilities
August 28, 2026 · BleepingComputer · Severity: HIGH
ServiceNow issued security patches for three maximum-severity vulnerabilities in its AI Platform that can be exploited in code injection, SQL injection, and privilege escalation attacks. The flaws, which impact the GraphQL API and system configuration upload processor, pose critical risks to unpatched instances. ServiceNow has updated hosted instances and provided patches for self-hosted customers.
Key Takeaways
- ServiceNow released patches for three new maximum-severity AI Platform vulnerabilities enabling code injection and SQL injection.
- These flaws allow unauthenticated attackers to perform privilege escalation and execute arbitrary SQL statements.
- Organizations running self-hosted instances must apply the updates manually to prevent potential exploitation.