ServiceNow Patches Four Flaws in AI Platform

ServiceNow said on August 27 that it had patched four vulnerabilities across its AI Platform and Now Platform, including three critical code-injection issues and one high-severity sandbox escape. The fixes cover hosted instances, while self-hosted customers received hotfixes for the Xanadu, Yokohama, Zurich, and Australia releases. ServiceNow said the critical bugs need no authentication or user interaction. A crafted request can be accepted as a trusted internal action, letting an attacker run code, create or modify records, issue SQL against the underlying database, or raise privileges inside the platform itself. That matters most for deployments that sit near HR, vendor, or finance workflows: a flaw in the platform layer can reach the records it brokers, and self-hosted instances do not get the benefit of vendor-side remediation until the local hotfix lands.

Part of the PlainSec briefing for 2026-08-31

Every edition of this story: ServiceNow Patches Four Flaws in AI Platform

Sources