# ServiceNow patches five AI Platform flaws, including two critical data risks

_Published Friday, September 25, 2026 at 9:21 AM EDT · Security · Latest · Tier 2 — Notable_

![ServiceNow patches five AI Platform flaws, including two critical data risks — Primary](https://cybersecuritynews.com/wp-content/uploads/2026/09/Critical-ServiceNow-Vulnerabilities-Let-Attackers-Bypass-Authorization-Update-Now.webp)

ServiceNow released fixes for five AI Platform vulnerabilities, including two critical flaws that could expose customer instance data to unauthenticated attackers. One, CVE-2026-13016, could permit database commands through SQL injection in certain circumstances. Another, CVE-2026-86860, could let an attacker extract data beyond intended access controls.

Customers in ServiceNow's August Patching Program have already received fixes, while self-hosted customers need to verify their versions and update. ServiceNow said it has found no evidence that attackers have exploited the flaws in the wild.

## Sources

- [cybersecuritynews.com](https://cybersecuritynews.com/critical-servicenow-vulnerabilities/)

---
Canonical: https://techandbusiness.org/newswire/0gJWdCZrNH-f9TCZLThe7G
Published: 2026-09-25T13:21:37.703Z
Story chronology: 2026-09-25T12:18:09.000Z
Retrieved: 2026-09-25T14:57:28.981Z
Publisher: Tech & Business (techandbusiness.org)
