Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OnePlus OxygenOS Critical Flaws Let Zero-Permission Apps Gain Root Access
September 25, 2026
Critical Linux Kernel Flaw (CVE-2024-0001) Lets Local Users Gain Root, Escape Containers
September 25, 2026
AI-Powered Botnet “DarkGate” Found Operating Inside Compromised Servers
September 25, 2026
Home/CyberSecurity News/Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization
CyberSecurity News

Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization

Key Takeaways ServiceNow has released critical security updates addressing five vulnerabilities within its AI Platform. Two critical flaws (CVE-2026-13016 and CVE-2026-86860) could allow...

Marcus Rodriguez
Marcus Rodriguez
September 25, 2026 3 Min Read
7 0

Key Takeaways

  • ServiceNow has released critical security updates addressing five vulnerabilities within its AI Platform.
  • Two critical flaws (CVE-2026-13016 and CVE-2026-86860) could allow unauthenticated attackers to access, modify, or extract sensitive instance data.
  • The vulnerabilities were identified through various channels, including internal testing and bug bounty programs.
  • While no in-the-wild exploitation has been observed, immediate patching is strongly recommended, especially for internet-facing instances.

ServiceNow has issued urgent security advisories and released patches for a set of five vulnerabilities affecting its AI Platform, two of which are rated critical. These flaws could potentially allow unauthorized individuals to bypass authentication mechanisms and gain access to, modify, or exfiltrate sensitive data from affected instances. The company is strongly urging self-hosted users to verify their current versions and apply the necessary updates without delay.

Table Of Content

  • Key Takeaways
  • Critical Vulnerabilities Detailed
  • What You Should Do

The security advisory from ServiceNow details the vulnerabilities, identified as CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860. These issues came to light through a combination of internal testing, customer assessments, responsible disclosures, and the vendor’s bug bounty program.

Although ServiceNow has confirmed that there is currently no evidence of these vulnerabilities being actively exploited in the wild, the potential technical repercussions necessitate prompt action. Rapid patching is particularly crucial for instances that are exposed to the public internet or are integral to sensitive enterprise workflows and data management.

Critical Vulnerabilities Detailed

The most severe vulnerability, CVE-2026-13016, is a critical SQL injection flaw impacting the ServiceNow AI Platform. Under specific conditions, an unauthenticated attacker could leverage this vulnerability to execute arbitrary SQL commands against the underlying database of an affected instance. Successful exploitation of this flaw could enable an attacker to read, modify, or even manipulate data stored within the ServiceNow instance. This poses significant risks for organizations that rely on ServiceNow for critical functions such as IT service management, security incident response, employee request processing, asset tracking, customer information, and various internal business operations.

Another critical vulnerability, CVE-2026-86860, is an authorization bypass issue. This flaw could permit an unauthenticated attacker to extract instance data, circumventing established access controls and allowing access to information beyond their intended permissions. ServiceNow has cautioned that exploitation of these critical flaws could lead to privilege escalation, granting attackers elevated access levels or data permissions they should not possess.

The September 2026 advisory KB3159623 further outlines three additional high-severity vulnerabilities related to authorization and access control weaknesses:

  • CVE-2026-86857: This is an authorization bypass flaw that could allow an authenticated user to access ServiceNow AI Platform data for which they lack proper entitlements, potentially leading to broader unintended access within the environment.
  • CVE-2026-86858: An improper access control issue, this vulnerability could, under certain circumstances, enable an unauthenticated attacker to create, modify, or delete instance data outside of their authorized permissions. Such actions could disrupt operational workflows, corrupt records, or compromise the integrity of security and operational data.
  • CVE-2026-86859: Similar to CVE-2026-86857, this is another authorization bypass vulnerability. However, this specific flaw could allow an unauthenticated attacker to access restricted data within the ServiceNow AI Platform.

ServiceNow has confirmed that customers enrolled in its August Patching Program have already received the necessary fixes. Self-hosted customers are urged to upgrade their instances or apply the relevant updates immediately. Patched releases include Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 4a W32, and Australia Patch 2 Hot Fix 4b W32. Additional remediated versions include Zurich Patch 10 Hot Fix 3b, Zurich Patch 11 Hot Fix 3, Australia Patch 4 Hot Fix 3, and Australia Patch 5.

What You Should Do

  • Immediately identify and confirm your current ServiceNow AI Platform version.
  • Apply the recommended patches or upgrade to a remediated release as detailed by ServiceNow, prioritizing internet-facing instances.
  • Review and audit administrative access privileges within your ServiceNow environment.
  • Implement enhanced monitoring for unusual database queries, unexpected data modifications, or any unauthorized access attempts after applying patches.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Attackers Exploit Business Emails for Malware Delivery

Next Post

Critical WordPress Comment2Shell RCE Vulnerability CVE-2022-0215 Patched

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Sauron Loader Malware Evades Detection with DLL Side-Loading
September 25, 2026
Critical WordPress Comment2Shell RCE Vulnerability CVE-2022-0215 Patched
September 25, 2026
Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization
September 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us