Patched isn’t proof you weren’t breached.

When a ServiceNow CVE drops you can check for free whether your release is affected. But a patched instance is not the same as one that was never hit — so the real question is “were we exploited in the window before we patched?” That’s a NIS2 Art. 23 / DORA Art. 19 reporting decision, answered from your own instance logs. It’s the part nobody else answers — and where this check goes.

How it works

  1. Pick the CVE or advisory.

    Tracked ServiceNow Now Platform CVEs and advisories, priority-ranked by CVSS, EPSS exploitation probability, CISA KEV, and public-exploit availability.

  2. Am I patched?free · no login · no instance access

    Enter your release and patch level and get a PATCHED / AFFECTED / NEEDS REVIEW verdict against the verified per-release fix points.

  3. Was I exploited before I patched?Enterprise

    Run one read-only Background Script and paste its output. We correlate your sys_audit / syslog_transaction / sysevent records across the disclosure→patch window and return EXERCISED / DORMANT / INVESTIGATE plus a downloadable evidence pack (PDF).

What you needYour release and patch level for the free check. An Enterprise plan and the ability to run a Background Script for the exploitation forensics.
What you getA plain verdict with the reasoning behind it — and, for the forensics step, a NIS2/DORA-ready evidence pack (PDF).
What stays privateThe free check runs in your browser — no login, no instance access. The forensics step is paste-driven (no OAuth); nothing is written to your instance.
How longThe free check takes about a minute. The forensics step is one script and one paste.
details ↗Verified
Priority Medium · 29CVSS 9.5EPSS

1 · Am I patched? free · no login · no instance access

Fix points by release

  • Brazil — fixed in Brazil EA / Brazil GA
  • Australia — fixed in Patch 2
  • Zurich — fixed in Patch 7b / Patch 9
  • Yokohama — fixed in Patch 12 Hot Fix 1b / Patch 13

You’re patched now. Were you exploited in the window before you patched? A patched instance is not the same as one that was never hit — and under DORA Article 19 and NIS2 Article 23, “were we breached?” is a reporting decision, not a guess.

2 · Was I exploited before I patched? Enterprise · paste-driven · no OAuth

Checking your plan…

Data: GitHub Advisory Database (CC-BY 4.0), NVD, and the CISA KEV catalog.