ServiceNow AI Platform Vulnerability Allows Remote Code Execution


ServiceNow has disclosed a critical security vulnerability in its AI Platform that could allow unauthenticated attackers to remotely execute code within the ServiceNow Sandbox environment.

Tracked as CVE-2026-0542, the flaw was formally published on February 25, 2026, under security advisory KB2693566.

Overview of the Vulnerability

The vulnerability exists within the ServiceNow AI Platform and can be exploited by an unauthenticated user under certain conditions to execute arbitrary code remotely.

While the attack is confined to the ServiceNow Sandbox, such execution capabilities can expose sensitive workflow data, automation logic, and enterprise integrations managed through the platform.

ServiceNow confirmed that, as of the advisory publication date, there is no evidence of active exploitation against customer instances in the wild.

FieldDetails
CVE IDCVE-2026-0542
Advisory IDKB2693566
SeverityCritical
Attack TypeRemote Code Execution (RCE)
Authentication RequiredNo (Unauthenticated)
Affected ProductServiceNow AI Platform
Exploitation in the WildNot detected
Advisory PublishedFebruary 25, 2026

Patch and Fixed Versions

ServiceNow proactively deployed a security update to hosted customer instances on January 6, 2026. Patches are also available for self-hosted customers and partners.

ReleaseFixed VersionAvailability
AustraliaTBDQ2 2026
ZurichPatch 4 Hotfix 3bFebruary 23, 2026
ZurichPatch 5January 12, 2026
YokohamaPatch 10 Hotfix 1bFebruary 18, 2026
YokohamaPatch 12February 6, 2026
XanaduPatch 11 Hotfix 1aFebruary 2, 2026

Organizations running ServiceNow should immediately apply the relevant patches listed above.

Customers who participated in the January 2026 Patching Program already received the appropriate update. Instances that did not receive a notification were confirmed as unaffected.

Security teams should verify their current release version and prioritize upgrading to the fixed builds, especially for internet-accessible or externally integrated ServiceNow deployments.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.



Source link