Executive brief
ServiceNow has fixed a critical security flaw in its AI platform that could allow an unauthorized person to run malicious code on the system. This platform is used to power artificial intelligence and automation features within the ServiceNow environment. If exploited, an attacker could potentially gain full control over the platform, leading to data theft or significant service disruptions.
Technical details
A remote code execution (RCE) vulnerability exists in the ServiceNow AI Platform due to a sandbox escape. An unauthenticated attacker can exploit this vulnerability over the network, though the attack complexity is rated as high. Successful exploitation allows for the execution of arbitrary code within the ServiceNow platform, potentially compromising the confidentiality, integrity, and availability of the entire system. ServiceNow has released patches for several family releases, including Australia, Yokohama, Zurich, and Brazil, and has already updated its hosted instances.
Affected products
- ServiceNow AI Platform Australia Patch 2, Yokohama Patch 12 Hot Fix 1b, Yokohama Patch 13, Zurich Patch 7b, Zurich Patch 9, Brazil EA, Brazil GA
Timeline
- 2026-07-13: disclosed
- 2026-07-13: advisory
- 2026-07-13: patched