ServiceNow has patched three CVSS 10.0 vulnerabilities in its AI Platform that allow unauthenticated, network-based attacks requiring no user interaction, including remote code execution, privilege escalation, and arbitrary SQL queries. Hosted instances were updated by ServiceNow, but organizations running self-hosted deployments must install the fixes across the Xanadu, Yokohama, Zurich, and Australia release families.
Source