# ServiceNow issues patches for three CVSS 10 code-injection flaws

_Monday, August 31, 2026 at 9:59 AM EDT · Security · Latest · Tier 1 — Major_

![ServiceNow issues patches for three CVSS 10 code-injection flaws — Primary](https://www.securityweek.com/wp-content/uploads/2026/06/ServiceNow.webp)

ServiceNow said it has deployed patches across hosted instances and released hotfixes for self-hosted deployments after disclosure of four vulnerabilities in its AI platform and Now Platform. Three flaws, rated CVSS 10, allow code execution, arbitrary data changes or arbitrary SQL statements in low-complexity attacks without authentication or user interaction. A fourth, rated 8.7, is a sandbox-escape issue that can enable code execution. The self-hosted hotfixes cover the Xanadu, Yokohama, Zurich and Australia releases.

## Sources

- [SecurityWeek](https://www.securityweek.com/servicenow-patches-3-critical-code-injection-vulnerabilities/)

---
Canonical: https://techandbusiness.org/newswire/ylSGZNL3eaUJMM3cemU36r
Retrieved: 2026-08-31T18:14:05.691Z
Publisher: Tech & Business (techandbusiness.org)
