ServiceNow has addressed four significant security vulnerabilities within its AI Platform, with three of these flaws receiving a critical CVSS rating of 10.0. These vulnerabilities could potentially be exploited by unauthenticated attackers, posing a severe risk to systems that have not yet implemented the necessary patches. The company has already issued security updates to its hosted instances and shared these updates with its partners and self-hosted customers. Organizations operating their own instances must ensure they apply these patches to safeguard their systems.

The advisory, published on August 27, 2026, specifies that the vulnerabilities allow a network-reachable attack with low complexity, requiring no user interaction or privileges. This creates a high impact on the confidentiality, integrity, and availability of both the vulnerable component and connected systems. This announcement follows an earlier advisory concerning CVE-2026-6875, a pre-authentication sandbox escape that was exploited in the wild, as reported by threat intelligence firm Defused.

ServiceNow confirmed their awareness of the recent reports of exploitation activity linked to CVE-2026-6875, emphasizing that no evidence suggests this affects ServiceNow-hosted instances. The company has been proactive in providing necessary updates and continues to work closely with customers to ensure effective patch application. Despite the critical nature of these new vulnerabilities, ServiceNow has not observed any active exploitation or public exploit code as of August 28, 2026. Security professionals and ServiceNow clients must remain vigilant and apply the necessary patches to mitigate these risks.