# ServiceNow patches three critical AI Platform flaws

_Friday, August 28, 2026 at 6:29 AM EDT · Security · Latest · Tier 1 — Major_

![ServiceNow patches three critical AI Platform flaws — Primary](https://www.bleepstatic.com/content/hl-images/2026/07/20/servicenow-headpic.jpg)

ServiceNow released patches for three maximum-severity vulnerabilities in its AI Platform: two code-injection flaws and an SQL-injection flaw. The company said unauthenticated attackers could use the issues in low-complexity attacks without user interaction, enabling arbitrary code execution, privilege escalation, or access to and modification of instance data. ServiceNow also patched a high-severity sandbox-escape issue affecting the platform. The company said it was not aware of malicious exploitation and advised customers to update or upgrade self-hosted instances.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/servicenow-warns-of-three-max-severity-security-vulnerabilities/)

---
Canonical: https://techandbusiness.org/newswire/hPWGZbhJv-SUSLW0ZYh5Oc
Retrieved: 2026-08-28T12:46:29.957Z
Publisher: Tech & Business (techandbusiness.org)
