[Security Advisory] September 2026 CVE Advisory Notification ServiceNow Posture September, 2026 Quick Summary What you need to know: On September 24, 2026, ServiceNow issued CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.Each of these security issues was identified through internal security testing, customer security assessments, or reports submitted through ServiceNow's responsible disclosure and bug bounty programs and was remediated independently. For security issues identified through responsible disclosure, researchers may choose to publish their findings.ServiceNow did not identify evidence of malicious exploitation related to these issues.The purpose of this article is to answer questions you may have about these issues and the security update. Background CVE-2026-86857 - PRB2033195 Based on the CVSS v4.0 calculator, we have assessed the risk posed by the vulnerability addressed in CVE-2026-86857 to be high. ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling further unintended access. CVE-2026-86858 - PRB2059173 Based on the CVSS v4.0 calculator, we have assessed the risk posed by the vulnerability addressed in CVE-2026-86858 to be high. ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete instance data beyond what was intended. CVE-2026-13016 - PRB2036897 Based on the CVSS v4.0 calculator, we have assessed the risk posed by the vulnerability addressed in CVE-2026-13016 to be critical. ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended. CVE-2026-86859 - PRB2055263 Based on the CVSS v4.0 calculator, we have assessed the risk posed by the vulnerability addressed in CVE-2026-86859 to be high. ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling further unintended access. CVE-2026-86860 - PRB2050429 Based on the CVSS v4.0 calculator, we have assessed the risk posed by the vulnerability addressed in CVE-2026-86860 to be critical. ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege escalation. Am I Affected? Customers who participate in the ServiceNow August Patching Program received the appropriate update, which are listed below. We recommend self-hosted customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so. ServiceNow AI Platform ReleaseVersion Updated Yokohama Patch 13 Hot Fix 5a Zurich Patch 10 Hot Fix 4a W32 Australia Patch 2 Hot Fix 4b W32 In addition, the below versions also contain remediations for all five CVEs tied to September's CVE batch: ServiceNow AI Platform ReleaseVersion Updated Zurich Patch 10 Hot Fix 3b Patch 11 Hot Fix 3 Australia Patch 4 Hot Fix 3 Patch 5 Is Customer Action Required? Please see the instructions in the previous section to determine if your instance is on the appropriate version. We recommend self-hosted customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so. Additional Resources KB3159625 – [Requires Now Support Login] September 2026 CVE Advisory NotificationKB3159626 – [Requires Now Support Login] Self-Hosted September 2026 CVE Advisory Notification KB3017795 - [Requires Now Support Login] ServiceNow Policy on Publishing Common Vulnerabilities and Exposures (CVE) https://www.cve.org/CVERecord?id=CVE-2026-86857 https://www.cve.org/CVERecord?id=CVE-2026-86858 https://www.cve.org/CVERecord?id=CVE-2026-13016 https://www.cve.org/CVERecord?id=CVE-2026-86859 https://www.cve.org/CVERecord?id=CVE-2026-86860 Change Log VersionPublishedSummary of Changes1.0September 24, 2026Initial publication