Threat Intelligence

ServiceNow Patches Critical Flaws Rated Maximum Severity — Act Now if You're Self-Hosted

The Hacker News · 28 Aug 2026
Key Takeaway If your business runs a self-hosted ServiceNow instance, check with your IT provider immediately to confirm the patch has been applied, as these flaws can be exploited without a login.

ServiceNow has released patches for four security vulnerabilities affecting its AI Platform, with three of them receiving a perfect 10.0 severity score under the industry-standard CVSS system. In certain circumstances, these flaws could be exploited by attackers who don't even need valid login credentials, potentially allowing them to execute malicious code or manipulate databases through SQL injection.

ServiceNow has already rolled out the fix automatically to its hosted (cloud) customers and made the update available to partners. However, organisations that run ServiceNow on their own infrastructure (self-hosted instances) will need to apply the patch manually — meaning any business in this category that hasn't yet updated remains exposed to serious risk.

Given the maximum severity rating and the fact that some of these flaws don't require authentication to exploit, this is a high-priority issue for any organisation using affected ServiceNow deployments. Businesses relying on partners or managed service providers to administer their ServiceNow environment should confirm with them directly that the patch has been applied.

ServiceNow critical vulnerability patch management

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.