ServiceNow CVE-2026-13016
Unauthenticated SQL Injection in the ServiceNow AI Platform
Risk & exploitation
Detection seeds: none indexed — public detection content (Sigma) that references this id; a seed is a starting point for a rule, not a verified fingerprint.
Disclosed 6 days ago, so the exploitation signals this score leans on — EPSS, CISA KEV and public-exploit indexing — have not had time to mean anything yet. Priority follows CVSS severity until they do, rather than reporting their absence as safety. EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-09-27). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
What it is. Someone who has never logged in can run SQL statements of their own against the database behind your instance. ServiceNow rates it critical, and the CVSS 4.0 vector puts confidentiality, integrity and availability all at High — this is the most severe of the five CVEs ServiceNow published on 24 September 2026.
Are you exposed? Any Yokohama, Zurich or Australia instance that has not reached the patch levels listed below. For a direct answer, use the Check your instance link further down this page and enter your release and patch level.
On Xanadu or older, ServiceNow published no fix in this batch — it patches only releases still in support. That is not the same as being unaffected. No fixed version exists for those releases, so nothing on this page can clear you, and the instance should be treated as exposed until it is upgraded.
What to do. Patch. Statement execution against the database is not something an application-layer control can contain, and the flaw needs no login, so there is no configuration workaround that buys you time.
Has it been used? Not visibly. There is no CISA KEV entry, no public exploit in the sources tracked here, and ServiceNow reports no evidence of malicious exploitation. The CVE is days old, so nobody has been looking for long.
For analysts. ServiceNow's CVSS 4.0 vector is AV:N/AC:L/AT:N/PR:N/UI:N with VC:H/VI:H/VA:H and SC:N/SI:N/SA:N, and the CWE is CWE-89. The internal problem record is PRB2036897. The unchanged subsequent-system metrics distinguish this from CVE-2026-86860 in the same batch, which scores SC:H/SI:H: here the damage is rated as staying within the instance and its database, rather than reaching beyond it.
What this page can tell you. The patch levels above were checked by a person against ServiceNow's KB3159625 on 2026-09-25, so the free check gives you a straight patched-or-affected answer from your release and patch level. Nobody has written a detection rule for this CVE yet, so the paid log check will tell you it could not look rather than guess — it never reports an attack it did not actually see.
Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Australia | Patch 2 Hot Fix 4b W32 / Patch 4 Hot Fix 3 / Patch 5 |
| Zurich | Patch 10 Hot Fix 3b / Patch 10 Hot Fix 4a W32 / Patch 11 Hot Fix 3 |
| Yokohama | Patch 13 Hot Fix 5a |
Source & attribution
Per-release fixed-in verified 2026-09-25 against ServiceNow's 'September 2026 CVE Advisory Notification' (KB3159625, login-gated, reviewed by a human) and cross-checked against the ServiceNow-authored CVE Record (CNA shortName: SN) as served by NVD. The two sources agree on all seven fixed-in boundaries across the three release families (Yokohama, Zurich, Australia). ServiceNow's CVE Records for this batch cite KB3159623; the article reviewed was KB3159625. No fix is published for Xanadu or earlier in this batch — those families are out of support, which is not the same as unaffected.
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(e)
- NIS2 Art.23§1
- DORA Art.9§1
- DORA Art.10§1
- DORA Art.19§1
- ISO A.8.8
- ISO A.8.3
- GDPR Art.32
- GDPR Art.33
Decision support, not a reporting determination.
References
- https://github.com/advisories/GHSA-89wx-h2m8-fc58
- https://nvd.nist.gov/vuln/detail/CVE-2026-13016
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159623
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159625
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159626
- https://www.cve.org/CVERecord?id=CVE-2026-13016
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.