CVE-2026-13016: ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerab
Summary
ServiceNow fixed a SQL injection vulnerability (a flaw that lets attackers run unauthorized database commands) in its AI Platform that could have allowed unauthenticated users to access or change data in the system. The company has already deployed security updates to its hosted instances and made updates available to partners and self-hosted customers, with no known malicious attacks reported so far.
Solution / Mitigation
ServiceNow deployed a security update to hosted instances and provided the update to partners and self-hosted customers. The company recommends that customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Vulnerability Details
EPSS: 0.0%
September 24, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-13016
First tracked: September 24, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 75%