ServiceNow issued urgent security updates on August 28, 2026, to address three severe vulnerabilities in its AI Platform. These maximum-severity flaws allow attackers to execute dangerous code injection and SQL injection attacks. The patches also fix a critical privilege escalation issue within the system.
The affected software is part of the ServiceNow AI Platform, which was previously referred to as the Now Platform. This component serves as a foundational layer for many enterprise applications. Security researchers identified specific weaknesses that could be exploited by malicious actors. The company acted quickly to release fixes for these newly discovered threats.
The three vulnerabilities present distinct risks to users of the platform. One flaw enables code injection, allowing attackers to run arbitrary commands on the server. A second vulnerability permits SQL injection, potentially granting unauthorized access to sensitive database information. The third issue involves privilege escalation, where a user with limited rights could gain higher administrative control.
These combined threats create a significant attack surface for organizations relying on the platform. Attackers could chain these exploits to compromise entire systems. The maximum severity rating indicates that exploitation is highly likely under normal operating conditions. ServiceNow emphasized the need for immediate patching to mitigate these risks effectively.
Security experts classify these bugs as maximum severity due to their potential impact. Such ratings are reserved for flaws that require no complex setup to exploit. Organizations using the unpatched versions face an elevated risk of data breaches. The timing of the release highlights the ongoing pressure on enterprise software vendors to secure AI-driven infrastructure.
The shift from the „Now Platformname to ”AI Platformreflects broader industry trends. As companies integrate artificial intelligence into core workflows, the underlying code becomes a prime target. ServiceNow’s response demonstrates a proactive approach to maintaining trust among its enterprise clients.
Which specific types of attacks do these vulnerabilities enable? The flaws allow for code injection, SQL injection, and privilege escalation. Attackers can use these methods to gain unauthorized control over the system or extract sensitive data.
What is the current name of the affected platform? The affected software is currently called the ServiceNow AI Platform. It was formerly known as the Now Platform before the recent rebranding.