ServiceNow CVEs & Security Advisories
Tracked ServiceNow Now Platform CVEs and security advisories, grouped by disclosure date — each scored by priority (CVSS severity, EPSS exploitation probability, CISA KEV, and public-exploit availability). For any CVE you can check whether you’re patched — and whether your instance was exploited in the window before you patched.
Run the exposure check →CVE data (EPSS, exploit signals) refreshed: 2026-09-03
| Priority | CVE / Advisory | Title | CVSS | EPSS | KEV | Exploit | Affected releases | Disclosed | Status |
|---|---|---|---|---|---|---|---|---|---|
| 20268 | |||||||||
| Critical · | CVE-2026-18885 | Unauthenticated Remote Code Execution in GraphQL Composite Data API | 10 | 0.4% | — | — | Australia, Zurich, Yokohama, Xanadu | 2026-08-27 | Verified |
| Critical · | CVE-2026-18886 | Unauthenticated Privilege Escalation via System Configuration Image Upload Processor | 10 | 0.2% | — | — | Australia, Zurich, Yokohama, Xanadu | 2026-08-27 | Verified |
| Critical · | CVE-2026-74820 | Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause | 10 | 0.2% | — | — | Australia, Zurich, Yokohama, Xanadu | 2026-08-27 | Verified |
| High · | CVE-2026-6876 | Sandbox Escape in Now Platform | 8.7 | 0.4% | — | — | Australia, Zurich, Yokohama, Xanadu | 2026-08-27 | Verified |
| High 61 | CVE-2026-6875 | Sandbox Escape in ServiceNow AI Platform | 9.5 | 78% | — | Yes | Brazil, Australia, Zurich, Yokohama | 2026-07-13 | Verified |
| Low 0 | SN-INCIDENT-2026-06-KB3067321 | Unauthenticated related-list-edit endpoint data access (June 2026 hosted incident) | — | — | — | — | Australia, Other releases (community-reported only) | 2026-04-01 | Unverified |
| Medium 19 | CVE-2026-0542 | Remote Code Execution in ServiceNow AI Platform | 9.2 | 0.6% | — | — | Australia, Zurich, Yokohama, Xanadu | 2026-02-25 | Verified |
| Medium 35 | CVE-2025-12420 | Unauthenticated Privilege Escalation in ServiceNow AI Platform | 9.3 | 47% | — | — | Now Assist AI Agents (sn_aia) 5.1.x, Now Assist AI Agents (sn_aia) 5.2.x, Virtual Agent API (sn_va_as_service) 3.x, Virtual Agent API (sn_va_as_service) 4.x | 2026-01-12 | Verified |
| 20255 | |||||||||
| Low 11 | CVE-2025-11449 | Reflected Cross Site Scripting in ServiceNow AI Platform | 5.3 | 0.3% | — | — | Australia, Zurich, Yokohama, Xanadu, Washington DC | 2025-10-10 | Verified |
| Low 11 | CVE-2025-11450 | Reflected Cross Site Scripting in ServiceNow AI Platform | 5.3 | 0.3% | — | — | Australia, Zurich, Yokohama, Xanadu, Washington DC | 2025-10-10 | Verified |
| Low 11 | CVE-2025-3089 | Broken Access Control in ServiceNow AI Platform | 5.3 | 0.4% | — | — | Zurich, Yokohama, Xanadu, Washington DC | 2025-08-12 | Verified |
| Medium 17 | CVE-2025-3648 | Data Inference in Now Platform via Conditional ACLs | 8.2 | 1.6% | — | — | All supported releases | 2025-07-08 | Unverified |
| Low 14 | CVE-2025-0337 | Authorization bypass in Now Platform | 7.1 | 0.4% | — | — | Yokohama, Xanadu, Washington DC | 2025-03-06 | Verified |
| 20246 | |||||||||
| Low 10 | CVE-2024-5890 | HTML Injection in the Assessment plugin | 5.1 | 0.3% | — | — | Washington DC, Vancouver, Utah | 2024-12-02 | Verified |
| Medium 19 | CVE-2024-8923 | Sandbox Escape in Now Platform | 9.3 | 1.1% | — | — | Xanadu, Washington DC, Vancouver | 2024-10-29 | Verified |
| Medium 18 | CVE-2024-8924 | Unauthenticated Blind SQL Injection in Now Platform Core | 8.7 | 0.5% | — | — | Utah, Vancouver, Washington DC, Xanadu | 2024-10-29 | Verified |
| Critical 99 | CVE-2024-4879 | Jelly Template Injection (SSTI) in UI Macros | 9.3 | 100% | KEV | Yes | Washington DC, Vancouver, Utah | 2024-07-10 | Verified |
| Critical 98 | CVE-2024-5217 | Incomplete Disallowed-Input List in GlideExpression (SSTI RCE) | 9.2 | 100% | KEV | Yes | Washington DC, Vancouver, Utah | 2024-07-10 | Verified |
| Medium 26 | CVE-2024-5178 | Incomplete Input Validation in SecurelyAccess API | 6.9 | 34% | — | — | Washington DC, Vancouver, Utah | 2024-07-10 | Verified |
| 20238 | |||||||||
| Low 0 | KB1553688 | Public Simple List Widget Data Exposure (misconfiguration) | — | — | — | — | All releases (configuration-dependent) | 2023-10-14 | Unverified |
| Low 9 | CVE-2023-1298 | ServiceNow Cross-Site Scripting | 4.3 | 0.4% | — | — | Utah, Tokyo, San Diego | 2023-07-06 | Verified |
| Medium 20 | CVE-2022-43684 | ACL bypass in Reporting functionality | 9.9 | 1.8% | — | — | Utah, Tokyo | 2023-06-13 | Verified |
| Low 9 | CVE-2023-1209 | ServiceNow Cross-Site Scripting | 4.3 | 0.4% | — | — | Utah, Tokyo, San Diego, Rome | 2023-05-23 | Verified |
| Low 12 | CVE-2022-46389 | Cross-Site Scripting (XSS) vulnerability found on logout functionality | 6.1 | 0.6% | — | — | Quebec, Rome, San Diego, Tokyo, Utah | 2023-04-17 | Unverified |
| Low 11 | CVE-2022-46886 | ServiceNow Open Redirect | 5.5 | 0.3% | — | — | Tokyo, San Diego, Rome, Quebec | 2023-04-14 | Verified |
| Medium 28 | CVE-2022-39048 | Cross-Site Scripting (XSS) vulnerability in ServiceNow UI page assessment_redirect | 6.1 | 1.1% | — | Yes | Quebec, Rome, San Diego, Tokyo, Utah | 2023-04-10 | Unverified |
| Low 11 | CVE-2022-42704 | ServiceNow Cross-Site Scripting | 5.4 | 0.4% | — | — | Quebec, Rome, San Diego | 2023-01-13 | Unverified |
| 20223 | |||||||||
| Medium 28 | CVE-2022-38463 | ServiceNow Cross-Site Scripting | 6.1 | 2.7% | — | Yes | San Diego | 2022-08-23 | Unverified |
| Low 12 | CVE-2022-38172 | ServiceNow Cross-Site Scripting | 6.1 | 0.6% | — | — | San Diego | 2022-08-23 | Unverified |
| Medium 31 | CVE-2021-45901 | ServiceNow Information Disclosure | 5.3 | 14% | — | Yes | Jakarta | 2022-02-10 | Unverified |
| 20201 | |||||||||
| Medium 26 | CVE-2019-20768 | ServiceNow Cross-Site Scripting | 5.4 | 0.7% | — | Yes | Kingston, London, Madrid | 2020-05-05 | Unverified |
| 20182 | |||||||||
| Medium 34 | CVE-2018-7748 | ServiceNow Remote Code Execution | 8.8 | 2.6% | — | Yes | Jakarta | 2018-08-03 | Unverified |
| Low 11 | CVE-2018-8720 | ServiceNow Cross-Site Scripting | 5.4 | 0.7% | — | — | All supported releases | 2018-03-15 | Unverified |
Priority blends CVSS, EPSS (exploitation probability), CISA KEV, and public-exploit availability — it is operational prioritization, not a NIS2/DORA reporting determination. A row showing a band with no number is led by CVSS severity: the CVE is too recently disclosed for EPSS, KEV or public-exploit indexing to mean anything yet, so their silence is not reported as safety. Detection fingerprints are authored and verified against live instances before they fire — unverified signals never produce a false “exploited” verdict. Rows marked Pending confirmation carry patch levels drafted from ServiceNow’s own CVE Record; Unverified ones are auto-imported from NVD / GitHub. Neither has been confirmed against the ServiceNow KB, so the patch check returns NEEDS REVIEW for both.
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.