ServiceNow CVE-2025-11449
Reflected Cross Site Scripting in ServiceNow AI Platform
Risk & exploitation
EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-09-02). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
What it is. A cross-site scripting flaw: an attacker can get script of their choosing to run inside another person's browser session, typically by persuading that person to open a crafted link. ServiceNow rates it 5.3 out of 10 — medium.
Are you exposed? Australia shipped already fixed at general availability, so any Australia instance is clear. Zurich, Yokohama, Xanadu and Washington DC need the patch levels listed below.
Releases older than Washington DC received no fix, because ServiceNow patches only releases still in support. That is not the same as being unaffected.
What to do. Patch on your normal cycle. This is a phishing-delivery and session-context problem rather than an instance-compromise one, and it needs a victim to act, so it does not warrant an emergency change. It matters most where an instance is public-facing through Service Portal, and least where platform access already sits behind SSO and network controls. On its own it is not evidence that anything has been compromised.
Has it been used? Not visibly. There is no CISA KEV entry and no public exploit in the sources tracked here.
For analysts. The vector is AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N. No privileges are needed, but the attack requires passive user interaction, and ServiceNow recorded no confidentiality, integrity or availability impact on the vulnerable system at all — only a low integrity impact on a subsequent one. That is the shape of a reflected payload executing in a victim's browser rather than anything reaching the instance itself. The CWE is CWE-79.
CVE-2025-11449 and CVE-2025-11450 were disclosed together on 2025-10-10 with identical scores, vectors and patch levels, and are very likely two findings of the same defect class from one review. Treat them as a single remediation item.
What this page can tell you. The patch levels below have been checked against ServiceNow's published advisory, so the free check gives you a straight patched-or-affected answer from your release and patch level. Nobody has written a detection rule for this CVE, so the paid log check will tell you it could not look rather than guess — it never reports an attack it did not actually see.
Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Australia | General Availability (GA) |
| Zurich | Patch 1 Hot Fix 1a / Patch 2 / Patch 3 |
| Yokohama | Patch 7 Hot Fix 2a / Patch 8 / Patch 9 |
| Xanadu | Patch 10 Hot Fix 1a / Patch 11 |
| Washington DC | Patch 10 Hot Fix 7b |
Source & attribution
Per-release fixed-in VERIFIED against the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[] boundaries, https://cveawg.mitre.org/api/cve/CVE-2025-11449 (retrieved 2026-06-08). The same patch matrix is in the login-gated ServiceNow KB; the public CVE Record is the citable source.
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(d)
- DORA Art.9§1
- DORA RTS Art.10
- ISO A.8.8
- ISO A.8.28
Decision support, not a reporting determination.
References
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.