CVE-2026-0542Patch

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow Sandbox.    ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and hot fixes. While we are not currently aware of exploitation against customer instances, we recommend customers promptly apply appropriate updates or upgrade if they have not already done so.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-653

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 6 mentions (2026-02-26); latest day: 1
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-02-26: 6Mentions · 2026-02-27: 1Mentions · 2026-03-05: 1Patch / Workaround · 2026-02-26: 5Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-26: 6Technical Details · 2026-02-27: 1Technical Details · 2026-03-05: 102-2602-2703-05
Signal classification2 categories
Patch
675.0%
Disclosure
225.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-266
Disclosure1Patch5
2026-02-271
Patch1
2026-03-051
Disclosure1
Full discourse8 posts
  • Gray Hats@the_yellow_fall
    Patch

    ServiceNow patches a critical 9.2 CVSS RCE vulnerability (CVE-2026-0542) in its AI sandbox. Unauthenticated users could execute code remotely. Patch now! #ServiceNow #AISecurity #CyberSecurity #CVE #RCE #InfoSec #CloudSecurity #Vulnerability #PatchAlert https://securityonline.info/sandbox-escape-critical-9-2-severity-rce-flaw-unmasked-in-servicenow-ai-platform/

    Post summary

    ServiceNow has released a patch for CVE-2026-0542, a critical RCE vulnerability in its AI sandbox that allows unauthenticated remote code execution.

    02052559
    10.4K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    ServiceNow AI Platform の脆弱性 CVE-2026-0542 が FIX:サンドボックス・エスケープによる RCE の可能性 https://iototsecnews.jp/2026/02/26/critical-servicenow-ai-platform-vulnerability-enables-remote-code-execution/ エンタープライズ向け管理プラットフォームの要である ServiceNow の、AI Platform のサンドボックス機能において、きわめて深刻な脆弱性 (CVSS:9.8:Critical) が発見されました。この脆弱性の最大のリスクは、未認証のリモート攻撃者に対して、サーバ上での任意のコード実行を許してしまう点にあります。 通常、ServiceNow のようなプラットフォームでは、信頼できないスクリプトや AI 処理はサンドボックスという隔離された制限環境での実行により安全性を担保しています。しかし、CVE-2026-0542 を悪用する攻撃者は、このサンドボックスの設計上の不備を突き、ホスト・システムやインスタンス全体へのアクセス権を奪取する恐れがあります。ご利用のチームは、ご注意ください。 #AIPlatform #CVE20260542 #ServiceNow #Vulnerability

    Post summary

    The article announces ServiceNow AI Platform’s CVE‑2026‑0542 as a critical sandbox‑escape remote code execution vulnerability (CVSS 9.8), but does not provide a PoC, exploit code, evidence of active exploitation, or patch details.

    01000162
    483 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical vulnerability CVE-2026-0542 in ServiceNow AI Platform allows remote code execution. Organizations urged to apply patches immediately to prevent potential exploits. Link: https://thedailytechfeed.com/critical-servicenow-ai-flaw-allows-remote-code-execution-urgent-patches-released/ #Security #Patch #Exploit #AI #Tech #Risk #Update #Software #Threat #Safety #IT #Network #Code #Data #Breach #Defense #Alert #CVE #Protection #Integrity

    Post summary

    ServiceNow AI Platform CVE-2026-0542 is a critical remote code execution flaw, and vendors have released urgent patches that organizations are urged to apply immediately to mitigate risk.

    0000062
    239 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-0542 ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated us… https://www.cve.org/CVERecord?id=CVE-2026-0542

    Post summary

    ServiceNow has released a patch for CVE-2026-0542, a remote code execution vulnerability in its AI platform that could be exploited by unauthenticated users.

    00000141
    56.6K followersView on X
  • ThreatCluster@threatcluster
    Patch

    ServiceNow patches critical AI Platform flaw CVE-2026-0542 that allowed unauthenticated remote code execution in the sandbox environment, posing significant risk to enterprise users. #Vulnerability https://threatcluster.io/cluster/servicenow-ai-platform-vulnerability-allows-remote-code-exec-9be3f960

    Post summary

    ServiceNow has released a patch for CVE-2026-0542, a critical flaw that allowed unauthenticated remote code execution in its AI Platform sandbox, mitigating the risk to enterprise users.

    0000043
    80 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 ServiceNow AI Platform Critical RCE (CVE-2026-0542) Patched: Unauth Code Execution in Sandbox ServiceNow fixed CVE-2026-0542 (CVSS 9.8), an unauthenticated remote code-execution flaw in the AI Platform’s Sandbox that could allow code injection and expose sensitive workflow logic, AI models, and embedded API keys. Organizations should patch affected release families and tighten AI/Sandbox access controls and monitoring to reduce internet-facing risk. 🎯 Target: Global/Enterprise SaaS (ITSM/HR/Support) #️⃣ Category: #Vulnerability #BlueTeam #AI_Threats 🔗 URL: https://cyberpress.org/critical-servicenow-ai-platform-flaw-allows-remote-code-execution-attacks/

    Post summary

    ServiceNow has released a patch for CVE‑2026‑0542, an unauthenticated RCE flaw in its AI Platform Sandbox, and urges organizations to apply the fix and tighten access controls.

    0000055
    220 followersView on X
  • CybrPulse@CybrPulse
    Patch

    ServiceNow patched CVE-2026-0542—a critical RCE in their AI Platform that let unauthenticated attackers execute code in the Sandbox. No auth required. Enterprise workflow access. Patched Jan 6 for hosted customers, but self-hosted need to update. https://gbhackers.com/servicenow-ai-platform-vulnerability/

    Post summary

    ServiceNow has patched CVE‑2026‑0542, a critical remote code execution flaw in its AI Platform; the patch was released Jan 6 for hosted customers, while self‑hosted users must apply updates.

    0000036
    16 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0542 Remote Code Execution in ServiceNow AI Platform via Unauthenticated Sandbox Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0542

    Post summary

    A new CVE (CVE-2026-0542) has been disclosed, describing a remote code execution vulnerability in ServiceNow AI Platform via an unauthenticated sandbox.

    0000067
    4.0K followersView on X

Explore more