ServiceNow CVEs & Security Advisories

Tracked ServiceNow Now Platform CVEs and security advisories, grouped by disclosure date — each scored by priority (CVSS severity, EPSS exploitation probability, CISA KEV, and public-exploit availability). For any CVE you can check whether you’re patched — and whether your instance was exploited in the window before you patched.

Run the exposure check →
PriorityCVE / AdvisoryTitleCVSSEPSSKEVExploitAffected releasesDisclosedStatus
20264
Medium 29CVE-2026-6875Sandbox Escape in ServiceNow AI Platform9.5Brazil, Australia, Zurich, Yokohama2026-07-13Verified
Low 0SN-INCIDENT-2026-06-KB3067321Unauthenticated related-list-edit endpoint data access (June 2026 hosted incident)Australia, Other releases (community-reported only)2026-04-01Unverified
Medium 19CVE-2026-0542ServiceNow Remote Code Execution9.20.3%Australia, Zurich, Yokohama, Xanadu2026-02-25Verified
Medium 19CVE-2025-12420ServiceNow Privilege Escalation9.30.1%Now Assist AI Agents (sn_aia) 5.1.x, Now Assist AI Agents (sn_aia) 5.2.x, Virtual Agent API (sn_va_as_service) 3.x, Virtual Agent API (sn_va_as_service) 4.x2026-01-12Verified
20255
Low 11CVE-2025-11449ServiceNow Cross-Site Scripting5.30.1%Australia, Zurich, Yokohama, Xanadu, Washington DC2025-10-10Verified
Low 11CVE-2025-11450ServiceNow Cross-Site Scripting5.30.1%Australia, Zurich, Yokohama, Xanadu, Washington DC2025-10-10Verified
Low 11CVE-2025-3089ServiceNow Access Control Flaw5.30.2%Zurich, Yokohama, Xanadu, Washington DC2025-08-12Verified
Medium 17CVE-2025-3648ServiceNow Access Control Flaw8.20.3%All supported releases2025-07-08Unverified
Low 14CVE-2025-0337ServiceNow Access Control Flaw7.10.0%Yokohama, Xanadu, Washington DC2025-03-06Verified
20246
Low 10CVE-2024-5890ServiceNow Cross-Site Scripting5.10.4%Washington DC, Vancouver, Utah2024-12-02Verified
Medium 19CVE-2024-8923ServiceNow Remote Code Execution9.30.9%Xanadu, Washington DC, Vancouver2024-10-29Verified
Medium 18CVE-2024-8924Unauthenticated Blind SQL Injection in Now Platform Core8.70.6%Utah, Vancouver, Washington DC, Xanadu2024-10-29Verified
Critical 97CVE-2024-4879Jelly Template Injection (SSTI) in UI Macros9.394%KEVYesWashington DC, Vancouver, Utah2024-07-10Verified
Critical 96CVE-2024-5217Incomplete Disallowed-Input List in GlideExpression (SSTI RCE)9.294%KEVYesWashington DC, Vancouver, Utah2024-07-10Verified
Low 14CVE-2024-5178ServiceNow Remote Code Execution6.91.9%Washington DC, Vancouver, Utah2024-07-10Verified
20238
Low 0KB1553688Public Simple List Widget Data Exposure (misconfiguration)All releases (configuration-dependent)2023-10-14Unverified
Low 9CVE-2023-1298ServiceNow Cross-Site Scripting4.31.2%Utah, Tokyo, San Diego2023-07-06Verified
Medium 20CVE-2022-43684ServiceNow Information Disclosure9.90.2%Utah, Tokyo2023-06-13Verified
Low 9CVE-2023-1209ServiceNow Cross-Site Scripting4.30.7%Utah, Tokyo, San Diego, Rome2023-05-23Verified
Low 12CVE-2022-46389ServiceNow Cross-Site Scripting6.10.7%Quebec, Rome, San Diego, Tokyo, Utah2023-04-17Unverified
Low 11CVE-2022-46886ServiceNow Open Redirect5.50.2%Tokyo, San Diego, Rome, Quebec2023-04-14Verified
Medium 33CVE-2022-39048ServiceNow Cross-Site Scripting6.117%YesQuebec, Rome, San Diego, Tokyo, Utah2023-04-10Unverified
Low 11CVE-2022-42704ServiceNow Cross-Site Scripting5.40.2%Quebec, Rome, San Diego2023-01-13Unverified
20223
High 44CVE-2022-38463ServiceNow Cross-Site Scripting6.148%YesSan Diego2022-08-23Unverified
Low 12CVE-2022-38172ServiceNow Cross-Site Scripting6.10.4%San Diego2022-08-23Unverified
Medium 32CVE-2021-45901ServiceNow Information Disclosure5.320%YesJakarta2022-02-10Unverified
20201
Medium 26CVE-2019-20768ServiceNow Cross-Site Scripting5.40.2%YesKingston, London, Madrid2020-05-05Unverified
20182
Medium 34CVE-2018-7748ServiceNow Remote Code Execution8.82.8%YesJakarta2018-08-03Unverified
Low 11CVE-2018-8720ServiceNow Cross-Site Scripting5.40.2%All supported releases2018-03-15Unverified

Priority blends CVSS, EPSS (exploitation probability), CISA KEV, and public-exploit availability — it is operational prioritization, not a NIS2/DORA reporting determination. Detection fingerprints are authored and verified against live instances before they fire — unverified signals never produce a false “exploited” verdict. CVEs marked Unverified have auto-imported metadata; their per-release patch levels are still being confirmed, so the patch check returns NEEDS REVIEW until verified.

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.