ServiceNow has patched a critical flaw in its AI Platform
ServiceNow has addressed a critical vulnerability, CVE-2026-0542 with a CVSS v4 score of 9.2, in its AI Platform. Under certain circumstances it could allow an unauthenticated attacker to remotely execute code within the ServiceNow Sandbox. Security updates were deployed to affected hosted customer instances on 6 January 2026, with corresponding patches made available to self-hosted customers and partners. The company states it is not aware of any exploitation in the wild. Customers should apply the relevant updates and confirm their instances run the fixed versions listed in ServiceNow's advisory KB2693566.
What this means for your organisation
Many Norwegian organisations use ServiceNow as the hub for case management, access requests and change control. That makes the platform an attractive target regardless of the AI features. The notable point here is the division of labour: hosted customers were patched by the vendor, while self-hosted customers have to act themselves. If you run self-hosted without a process that captures vendor advisories, you stay exposed long after the fix existed.
Berigo recommends
- Confirm which version your instances actually run, and that it is among the fixed releases in KB2693566.
- Establish in writing who is responsible for patching each SaaS platform you use, you or the vendor.
- Subscribe to security advisories from critical SaaS providers and feed them into vulnerability management alongside everything else.
- Set notification deadlines for security incidents in the contracts when they come up for renewal.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch