← nejvýznamnější zprávy · všechny zprávy

SPOJENO AI EPSS 0.00 (nejvyšší)

ServiceNow AI Platform - Multiple Severe Vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv4.0: 9.3, CVEs: CVE-2026-13016, CVE-2026-86857, CVE-2026-86858, CVE-2026-86859, CVE-2026-86860, Summary: ServiceNow has fixed multiple vulnerabilities in the ServiceNow AI Platform. Unauthenticated attackers could exploit the vulnerabilities to execute SQL queries, read or modify database information, extract sensitive data, escalate privileges or create, modify and delete instance records. A separate authorization…

Číst originál na NCSC-FI →

3 zprávy z 3 zdrojů · první 25. 9. 04:00 · poslední 25. 9. 14:56 CZ · EN/orig

ServiceNow CA IT FI

tg: zranitelnost

CVE v události 5

CVEhodnoceníKEVEPSS
CVE-2026-13016 9.3 4.0 · SN – 0.00
CVE-2026-86857 8.4 4.0 · SN – 0.00
CVE-2026-86858 8.7 4.0 · SN – 0.00
CVE-2026-86859 8.7 4.0 · SN – 0.00
CVE-2026-86860 9.3 4.0 · SN – 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.3.

Jak se o tom psalo 3

  1. · Cyber Centre Kanada CA

    ServiceNow security advisory (AV26-963)

    Serial number: AV26-963Date: September 25, 2026 As of September 24, 2026, ServiceNow is affected by vulnerabilities in the following product: ServiceNow AI Platform Versions prior to Australia Patch 2 Hot Fix 4b W32 Versions prior to Australia Patch 4 Hot Fix 3 Versions prior to Australia Patch 5 Versions prior to Yokohama Patch 13 Hot Fix 5a Versions prior to Zurich Patch 10 Hot Fix 3b Versions prior to Zurich Patch 10 Hot Fix 4a W32 Versions prior to Zurich Patch 11 Hot Fix 3 The Cyber Centre…

  2. · CSIRT Itálie (ACN) IT

    Risolte vulnerabilità in ServiceNow

    Rilasciati aggiornamenti di sicurezza che risolvono 5 vulnerabilità, di cui 2 con gravità "critica" e 3 con gravità "alta", in ServiceNow AI Platform, piattaforma di intelligenza artificiale e automazione di ServiceNow, progettata per integrare funzionalità di AI generativa, machine learning e workflow automation nei processi aziendali e IT.

  3. · NCSC-FI FI nadpis události

    ServiceNow AI Platform - Multiple Severe Vulnerabilities

    Classification: Severe, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv4.0: 9.3, CVEs: CVE-2026-13016, CVE-2026-86857, CVE-2026-86858, CVE-2026-86859, CVE-2026-86860, Summary: ServiceNow has fixed multiple vulnerabilities in the ServiceNow AI Platform. Unauthenticated attackers could exploit the vulnerabilities to execute SQL queries, read or modify database information, extract sensitive data, escalate privileges or create, modify and delete instance records. A separate authorization…