A critical SQL injection vulnerability exposes enterprise data across customer instances.
ServiceNow disclosed multiple critical flaws in its AI Platform on September 28, 2026. The company urged enterprise clients to apply security patches immediately to reduce the risk of unauthorized access and data modification across customer instances.
The most severe vulnerability, tracked as CVE-2026-13016, involves an SQL injection flaw. It could allow unauthenticated attackers to access or alter sensitive instance data, exposing ticket histories, employee records, and workflow logic across IT, human resources, and customer operations.
Alongside the disclosure, ServiceNow announced a new partnership with Reco. The collaboration will integrate Reco's AI agent security controls directly into the ServiceNow AI Platform to strengthen governance and risk controls.
Newsletter
Markets in your inbox, weekly
Latin America-focused analysis, investment themes and the week in finance.
Keep reading