
CISA Orders Federal Agencies to Patch ServiceNow AI Vulnerabilities Under Active Exploitation
The Cybersecurity and Infrastructure Security Agency has ordered federal civilian agencies to patch three critical ServiceNow AI platform vulnerabilities by September 4, 2026. The flaws, carrying maximum severity scores of 10.0, impact the Washington DC, Vancouver, and Utah releases. ServiceNow confirmed the security issues stem from default configurations permitting unauthenticated...








