On September 24, 2026, ServiceNow published advisory KB3159623 for five vulnerabilities in its AI Platform. The batch includes two critical and three high-severity issues, with impacts ranging from authorization bypass to access or modification of instance data.
Canada’s Cyber Centre relayed the advisory on September 25. ServiceNow says hosted instances were remediated; partners and customers operating their own environments must confirm their patch level and upgrade path.
The five vulnerabilities
The batch includes CVE-2026-13016, a SQL injection issue, CVE-2026-86860, a missing-authorization issue, and CVE-2026-86857, CVE-2026-86858 and CVE-2026-86859 involving access to or manipulation of data. Consult the vendor advisory for exact vectors and fixed releases.
These descriptions express potential capabilities; they do not prove that a particular instance was accessed or changed. That distinction matters when deciding how to investigate and respond.
Compare the release families
Published thresholds differ across Australia, Yokohama and Zurich. The Canadian advisory cites Australia Patch 2 Hot Fix 4b W32, Australia Patch 4 Hot Fix 3 or Patch 5, Yokohama Patch 13 Hot Fix 5a and several Zurich levels.
Identify the family, patch and hot fixes actually installed. A hosted instance, partner environment and self-managed integration may not follow the same maintenance path.
Patch and confirm the state
Ask the team operating the instance to confirm the update, then verify the level in the console and change records. For partner or self-managed environments, follow KB3159623 and the applicable upgrade instructions.
Preserve useful evidence before changing access rules or data. General security guidance does not replace confirmation of the installed patch.
Data, integrations and privilege
Map administrator roles, API integrations and the tables or workflows reachable by AI Platform. Look for new accounts, privilege changes, unusual API calls and data modifications that do not match a planned operation.
ServiceNow and institutional sources reported no known malicious exploitation at publication time. Treat that statement as a point-in-time visibility statement, not as a guarantee for an unverified instance.
How Soclyde fits
Soclyde does not patch ServiceNow or determine whether an instance was used by a third party. It can help organise administrator access and integration secrets in an encrypted local-first vault, with a distinct value for each service.
That organisation reduces secret copies during an access review without replacing role controls, logs or ServiceNow remediation.
The takeaway
ServiceNow fixed five AI Platform vulnerabilities, with different thresholds by release family. Confirm the hot fix, review access and inspect data before drawing conclusions. Read the secure password generator guide or contact Soclyde.



