← Back to Feed

ServiceNow warns of three max severity security vulnerabilities

August 28, 2026 · BleepingComputer · Severity: HIGH

ServiceNow issued security patches for three maximum-severity vulnerabilities in its AI Platform that can be exploited in code injection, SQL injection, and privilege escalation attacks. The flaws, which impact the GraphQL API and system configuration upload processor, pose critical risks to unpatched instances. ServiceNow has updated hosted instances and provided patches for self-hosted customers.

Key Takeaways

  • ServiceNow released patches for three new maximum-severity AI Platform vulnerabilities enabling code injection and SQL injection.
  • These flaws allow unauthenticated attackers to perform privilege escalation and execute arbitrary SQL statements.
  • Organizations running self-hosted instances must apply the updates manually to prevent potential exploitation.
☕ Buy a Coffee