Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ServiceNow — Vulnerabilities & Security Advisories 31

Browse all 31 CVE security advisories affecting ServiceNow. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ServiceNow operates as a cloud-based platform primarily used for IT service management, automating workflows for incident, change, and problem management across enterprise environments. Its architecture, which integrates numerous modules and third-party integrations, has historically exposed it to diverse vulnerability classes. Recorded Common Vulnerabilities and Exposures (CVEs) frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from complex input validation failures or insecure direct object references within its web interface. While the platform employs robust encryption and access controls, its expansive attack surface presents significant risks if misconfigured. Notable security incidents have included data exfiltration attempts and unauthorized access due to weak authentication mechanisms, highlighting the critical importance of rigorous patch management and strict identity governance to mitigate potential exploitation of these systemic weaknesses.

Found 14 results / 31 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-86860 Unauthenticated Sensitive Data Disclosure in ServiceNow AI Platform — ServiceNow AI Platform 9.3 Critical 2026-09-24
CVE-2026-86859 Unauthenticated Arbitrary Record Disclosure in ServiceNow AI Platform — ServiceNow AI Platform 8.7 High 2026-09-24
CVE-2026-13016 Unauthenticated SQL Injection in ServiceNow AI Platform — ServiceNow AI Platform 9.3 Critical 2026-09-24
CVE-2026-86858 Unauthenticated Privilege Escalation via GraphQL in ServiceNow AI Platform — ServiceNow AI Platform 8.7 High 2026-09-24
CVE-2026-86857 Authorization Bypass in ServiceNow AI Platform — ServiceNow AI Platform 8.4 High 2026-09-24
CVE-2026-74820 Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause — ServiceNow AI Platform 10.0 Critical 2026-08-27
CVE-2026-18886 Unauthenticated Privilege Escalation via System Configuration Image Upload Processor — ServiceNow AI Platform 10.0 Critical 2026-08-27
CVE-2026-18885 Unauthenticated Remote Code Execution in GraphQL Composite Data API — ServiceNow AI Platform 10.0 Critical 2026-08-27
CVE-2026-6876 Sandbox Escape in ServiceNow AI Platform — ServiceNow AI Platform 10.0 Critical 2026-08-27
CVE-2026-6875 Sandbox Escape in ServiceNow AI Platform — ServiceNow AI Platform 9.5 Critical 2026-07-13
CVE-2026-0542 Remote Code Execution in ServiceNow AI Platform — ServiceNow AI Platform CWE-653 9.8AI Critical AI 2026-02-25
CVE-2025-11449 Reflected Cross Site Scripting in ServiceNow AI Platform — ServiceNow AI Platform CWE-79 6.1AI Medium AI 2025-10-10
CVE-2025-11450 Reflected Cross Site Scripting in ServiceNow AI Platform — ServiceNow AI Platform CWE-79 6.1AI Medium AI 2025-10-10
CVE-2025-3089 Broken Access Control in ServiceNow AI Platform — ServiceNow AI Platform CWE-639 6.5AI Medium AI 2025-08-12

This page lists every published CVE security advisory associated with ServiceNow. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.