ServiceNow patches three top-severity flaws in its AI platform
Three of the four bugs score a maximum 10.0 on the industry severity scale, and one can be triggered by an attacker who has not logged in.

Key points
- ServiceNow has patched four security flaws in its AI Platform, the software many large companies use to run their IT and HR workflows.
- Three of the four bugs carry the maximum severity score of 10.0 out of 10 on the industry-standard CVSS scale.
- At least one of the flaws can be exploited by an attacker who has not signed in to the system.
- ServiceNow has already updated the versions it hosts for customers, and pushed the fix to partners and self-hosted customers.
- Companies running their own copies of ServiceNow have to install the update themselves, which is where most of the real-world risk now sits.
ServiceNow, the workflow software used by most of the Fortune 500 to run internal help desks, HR requests and IT tickets, has shipped patches for four vulnerabilities in its AI Platform. Three of them are as bad as bug ratings get.
The flaws were disclosed this week and first reported by The Hacker News. Each of the top three scores 10.0 on the Common Vulnerability Scoring System, or CVSS, the standard 0-to-10 scale the industry uses to rank how dangerous a software bug is. A 10.0 means easy to exploit, and devastating when it works.
In practice, that combination is rare. Vendors usually argue a bug down to a 9-point-something by pointing at some precondition. Not here.
What can an attacker actually do?
According to ServiceNow's advisory, the worst of the bugs can be triggered by an unauthenticated attacker, meaning someone who has not logged in and does not need a stolen password. In the right conditions they can run their own code on the server and pull data out of the underlying database using SQL, the language applications use to talk to their databases.
For a platform that typically holds employee records, internal tickets, vendor contracts and change-management history, that is about as sensitive as enterprise software gets. One thing the post-mortem will say, if any of these are exploited in the wild, is that the blast radius was the entire company's operational memory.
Who is protected already, and who is not?
Customers on ServiceNow-hosted instances are the lucky ones. ServiceNow says it has already deployed the fix to those tenants, the same way a cloud provider like AWS or Azure would patch a managed service without asking.
Partners and self-hosted customers, the organisations that run ServiceNow inside their own data centres or in their own cloud accounts, have been given the update and now have to apply it themselves. That is where the failure mode here lives. Self-hosted enterprise software famously drifts. Change windows get pushed, an upgrade breaks a custom workflow, and six months later the box is still on the vulnerable build.
If you run ServiceNow in-house, the operational takeaway is short: check your version against the fixed builds in ServiceNow's advisory this week, not next sprint.
Should ordinary people worry?
Probably not directly, but indirectly, yes. You are unlikely to log in to ServiceNow yourself. Your employer's IT help desk almost certainly does, and so does the HR system that holds your payslip history, your address and your bank details.
If your company runs its own copy of ServiceNow and is slow to patch, an attacker who chains these bugs could reach that data. There is nothing an individual employee can do about a server-side flaw. What you can do: be a bit more suspicious of unexpected emails claiming to come from your IT or HR portal over the coming weeks, because attackers love to piggyback on real vendor news.
Common questions
What is a CVSS 10.0 score?
It is the maximum severity rating a software bug can be given. It signals the flaw is easy to exploit remotely, needs no login, and hands the attacker deep control or data access.
What should ServiceNow customers do right now?
If ServiceNow hosts your instance, you are already patched. If you run it yourself, apply the update from ServiceNow's advisory this week and check no version has been missed in a lower environment.



