Vulnerability
Published 2026-09-24
Verified 2026-09-27

ServiceNow AI Platform Sept CVE advisory (CVE-2026-13016 / CVE-2026-86860 CVSS 9.3): unauth SQLi + data disclosure — KB3159623

ServiceNow September 2026 CVE Advisory (KB3159623; CNA records published 24 September 2026) remediates five ServiceNow AI Platform flaws. Lead criticals: CVE-2026-13016 (CVSS 4.0 9.3) — unauthenticated SQL injection enabling arbitrary SQL against the instance database and unintended data read/modify; CVE-2026-86860 (CVSS 4.0 9.3) — missing authorization / unauthenticated sensitive data disclosure with privilege escalation. Highs: CVE-2026-86858 (8.7) improper access control via GraphQL allowing unauth create/modify/delete of instance data; CVE-2026-86859 (8.7) unauthenticated authorization bypass / arbitrary record disclosure; CVE-2026-86857 (8.4) authenticated authorization bypass within AI Platform data. ServiceNow states no evidence of malicious exploitation; hosted instances received vendor updates (August Patching Program participants already covered); self-hosted/partners must apply patched releases. Distinct from August desk cards cve-2026-74820 / cve-2026-18885 / cve-2026-18886 / cve-2026-6876 (KB3152242). Primary: ServiceNow KB3159623 + CVE.org/NVD CNA metrics; wire: Cyber Security News 25 Sep 2026.

Product
ServiceNow AI Platform
Versions
Affected: builds before Yokohama Patch 13 Hot Fix 5a; Zurich Patch 10 Hot Fix 3b / Patch 10 Hot Fix 4a W32 / Patch 11 Hot Fix 3; Australia Patch 2 Hot Fix 4b W32 / Patch 4 Hot Fix 3 / Patch 5 (per CNA lessThan rows). Hosted: vendor-deployed. Self-hosted: upgrade to those patched releases.
CVSS
(CVSS 4.0, ServiceNow CNA — CVE-2026-13016 / CVE-2026-86860)
Exploited in Australia?
unknown
Patch to
Confirm hosted instance received the September advisory update. Self-hosted: apply Yokohama P13 HF5a, Zurich P10 HF3b / P10 HF4a W32 / P11 HF3, or Australia P2 HF4b W32 / P4 HF3 / P5. Monitor unusual DB queries, unexpected record changes, and unauthorized AI Platform access after patching.

Primary: ServiceNow — KB3159623 September 2026 CVE Advisory · Vendor: ServiceNow (vendor September 2026 CVE advisory) · CVE: CVE-2026-13016, CVE-2026-86860, CVE-2026-86858, CVE-2026-86859, CVE-2026-86857, CVE-2026-74820, CVE-2026-18885, CVE-2026-18886, CVE-2026-6876 · CVE.org — CVE-2026-13016 (ServiceNow CNA, CVSS 4.0 9.3)

vulnerabilities cloud ai identity