← All CVEs & advisories

ServiceNow CVE-2025-11449

Reflected Cross Site Scripting in ServiceNow AI Platform

XSSCVSS 4.0 5.3Priority 11Disclosed 2025-10-10Verified

Risk & exploitation

PriorityLow · 11/100
EPSS0.003 · 25.7th pct
CISA KEVNo
Public exploitNone indexed

EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-09-02). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

What it is. A cross-site scripting flaw: an attacker can get script of their choosing to run inside another person's browser session, typically by persuading that person to open a crafted link. ServiceNow rates it 5.3 out of 10 — medium.

Are you exposed? Australia shipped already fixed at general availability, so any Australia instance is clear. Zurich, Yokohama, Xanadu and Washington DC need the patch levels listed below.

Releases older than Washington DC received no fix, because ServiceNow patches only releases still in support. That is not the same as being unaffected.

What to do. Patch on your normal cycle. This is a phishing-delivery and session-context problem rather than an instance-compromise one, and it needs a victim to act, so it does not warrant an emergency change. It matters most where an instance is public-facing through Service Portal, and least where platform access already sits behind SSO and network controls. On its own it is not evidence that anything has been compromised.

Has it been used? Not visibly. There is no CISA KEV entry and no public exploit in the sources tracked here.

For analysts. The vector is AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N. No privileges are needed, but the attack requires passive user interaction, and ServiceNow recorded no confidentiality, integrity or availability impact on the vulnerable system at all — only a low integrity impact on a subsequent one. That is the shape of a reflected payload executing in a victim's browser rather than anything reaching the instance itself. The CWE is CWE-79.

CVE-2025-11449 and CVE-2025-11450 were disclosed together on 2025-10-10 with identical scores, vectors and patch levels, and are very likely two findings of the same defect class from one review. Treat them as a single remediation item.

What this page can tell you. The patch levels below have been checked against ServiceNow's published advisory, so the free check gives you a straight patched-or-affected answer from your release and patch level. Nobody has written a detection rule for this CVE, so the paid log check will tell you it could not look rather than guess — it never reports an attack it did not actually see.

Affected releases & fixed-in

ReleaseFixed in
AustraliaGeneral Availability (GA)
ZurichPatch 1 Hot Fix 1a / Patch 2 / Patch 3
YokohamaPatch 7 Hot Fix 2a / Patch 8 / Patch 9
XanaduPatch 10 Hot Fix 1a / Patch 11
Washington DCPatch 10 Hot Fix 7b
Source & attribution

Per-release fixed-in VERIFIED against the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[] boundaries, https://cveawg.mitre.org/api/cve/CVE-2025-11449 (retrieved 2026-06-08). The same patch matrix is in the login-gated ServiceNow KB; the public CVE Record is the citable source.

Regulatory mapping

Decision support, not a reporting determination.

Check your instance for CVE-2025-11449

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.

ServiceNow CVE-2025-11449: affected versions & exposure check — Nowisor | nowisor