ServiceNow CVEs & Security Advisories
Tracked ServiceNow Now Platform CVEs and security advisories, grouped by disclosure date — each scored by priority (CVSS severity, EPSS exploitation probability, CISA KEV, and public-exploit availability). For any CVE you can check whether you’re patched — and whether your instance was exploited in the window before you patched.
Run the exposure check →| Priority | CVE / Advisory | Title | CVSS | EPSS | KEV | Exploit | Affected releases | Disclosed | Status |
|---|---|---|---|---|---|---|---|---|---|
| 20264 | |||||||||
| Medium 29 | CVE-2026-6875 | Sandbox Escape in ServiceNow AI Platform | 9.5 | — | — | — | Brazil, Australia, Zurich, Yokohama | 2026-07-13 | Verified |
| Low 0 | SN-INCIDENT-2026-06-KB3067321 | Unauthenticated related-list-edit endpoint data access (June 2026 hosted incident) | — | — | — | — | Australia, Other releases (community-reported only) | 2026-04-01 | Unverified |
| Medium 19 | CVE-2026-0542 | ServiceNow Remote Code Execution | 9.2 | 0.3% | — | — | Australia, Zurich, Yokohama, Xanadu | 2026-02-25 | Verified |
| Medium 19 | CVE-2025-12420 | ServiceNow Privilege Escalation | 9.3 | 0.1% | — | — | Now Assist AI Agents (sn_aia) 5.1.x, Now Assist AI Agents (sn_aia) 5.2.x, Virtual Agent API (sn_va_as_service) 3.x, Virtual Agent API (sn_va_as_service) 4.x | 2026-01-12 | Verified |
| 20255 | |||||||||
| Low 11 | CVE-2025-11449 | ServiceNow Cross-Site Scripting | 5.3 | 0.1% | — | — | Australia, Zurich, Yokohama, Xanadu, Washington DC | 2025-10-10 | Verified |
| Low 11 | CVE-2025-11450 | ServiceNow Cross-Site Scripting | 5.3 | 0.1% | — | — | Australia, Zurich, Yokohama, Xanadu, Washington DC | 2025-10-10 | Verified |
| Low 11 | CVE-2025-3089 | ServiceNow Access Control Flaw | 5.3 | 0.2% | — | — | Zurich, Yokohama, Xanadu, Washington DC | 2025-08-12 | Verified |
| Medium 17 | CVE-2025-3648 | ServiceNow Access Control Flaw | 8.2 | 0.3% | — | — | All supported releases | 2025-07-08 | Unverified |
| Low 14 | CVE-2025-0337 | ServiceNow Access Control Flaw | 7.1 | 0.0% | — | — | Yokohama, Xanadu, Washington DC | 2025-03-06 | Verified |
| 20246 | |||||||||
| Low 10 | CVE-2024-5890 | ServiceNow Cross-Site Scripting | 5.1 | 0.4% | — | — | Washington DC, Vancouver, Utah | 2024-12-02 | Verified |
| Medium 19 | CVE-2024-8923 | ServiceNow Remote Code Execution | 9.3 | 0.9% | — | — | Xanadu, Washington DC, Vancouver | 2024-10-29 | Verified |
| Medium 18 | CVE-2024-8924 | Unauthenticated Blind SQL Injection in Now Platform Core | 8.7 | 0.6% | — | — | Utah, Vancouver, Washington DC, Xanadu | 2024-10-29 | Verified |
| Critical 97 | CVE-2024-4879 | Jelly Template Injection (SSTI) in UI Macros | 9.3 | 94% | KEV | Yes | Washington DC, Vancouver, Utah | 2024-07-10 | Verified |
| Critical 96 | CVE-2024-5217 | Incomplete Disallowed-Input List in GlideExpression (SSTI RCE) | 9.2 | 94% | KEV | Yes | Washington DC, Vancouver, Utah | 2024-07-10 | Verified |
| Low 14 | CVE-2024-5178 | ServiceNow Remote Code Execution | 6.9 | 1.9% | — | — | Washington DC, Vancouver, Utah | 2024-07-10 | Verified |
| 20238 | |||||||||
| Low 0 | KB1553688 | Public Simple List Widget Data Exposure (misconfiguration) | — | — | — | — | All releases (configuration-dependent) | 2023-10-14 | Unverified |
| Low 9 | CVE-2023-1298 | ServiceNow Cross-Site Scripting | 4.3 | 1.2% | — | — | Utah, Tokyo, San Diego | 2023-07-06 | Verified |
| Medium 20 | CVE-2022-43684 | ServiceNow Information Disclosure | 9.9 | 0.2% | — | — | Utah, Tokyo | 2023-06-13 | Verified |
| Low 9 | CVE-2023-1209 | ServiceNow Cross-Site Scripting | 4.3 | 0.7% | — | — | Utah, Tokyo, San Diego, Rome | 2023-05-23 | Verified |
| Low 12 | CVE-2022-46389 | ServiceNow Cross-Site Scripting | 6.1 | 0.7% | — | — | Quebec, Rome, San Diego, Tokyo, Utah | 2023-04-17 | Unverified |
| Low 11 | CVE-2022-46886 | ServiceNow Open Redirect | 5.5 | 0.2% | — | — | Tokyo, San Diego, Rome, Quebec | 2023-04-14 | Verified |
| Medium 33 | CVE-2022-39048 | ServiceNow Cross-Site Scripting | 6.1 | 17% | — | Yes | Quebec, Rome, San Diego, Tokyo, Utah | 2023-04-10 | Unverified |
| Low 11 | CVE-2022-42704 | ServiceNow Cross-Site Scripting | 5.4 | 0.2% | — | — | Quebec, Rome, San Diego | 2023-01-13 | Unverified |
| 20223 | |||||||||
| High 44 | CVE-2022-38463 | ServiceNow Cross-Site Scripting | 6.1 | 48% | — | Yes | San Diego | 2022-08-23 | Unverified |
| Low 12 | CVE-2022-38172 | ServiceNow Cross-Site Scripting | 6.1 | 0.4% | — | — | San Diego | 2022-08-23 | Unverified |
| Medium 32 | CVE-2021-45901 | ServiceNow Information Disclosure | 5.3 | 20% | — | Yes | Jakarta | 2022-02-10 | Unverified |
| 20201 | |||||||||
| Medium 26 | CVE-2019-20768 | ServiceNow Cross-Site Scripting | 5.4 | 0.2% | — | Yes | Kingston, London, Madrid | 2020-05-05 | Unverified |
| 20182 | |||||||||
| Medium 34 | CVE-2018-7748 | ServiceNow Remote Code Execution | 8.8 | 2.8% | — | Yes | Jakarta | 2018-08-03 | Unverified |
| Low 11 | CVE-2018-8720 | ServiceNow Cross-Site Scripting | 5.4 | 0.2% | — | — | All supported releases | 2018-03-15 | Unverified |
Priority blends CVSS, EPSS (exploitation probability), CISA KEV, and public-exploit availability — it is operational prioritization, not a NIS2/DORA reporting determination. Detection fingerprints are authored and verified against live instances before they fire — unverified signals never produce a false “exploited” verdict. CVEs marked Unverified have auto-imported metadata; their per-release patch levels are still being confirmed, so the patch check returns NEEDS REVIEW until verified.
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.