VYPR

ServiceNow AI Platform

by Servicenow

CVEs (10)

  • CVE-2025-12420CriJan 12, 2026
    risk 0.67cvss 9.8epss 0.53

    A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a…

  • CVE-2026-74820CriAug 27, 2026
    risk 0.65cvss epss 0.00

    ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and…

  • CVE-2026-6876CriAug 27, 2026
    risk 0.65cvss epss 0.00

    ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow…

  • CVE-2026-18886CriAug 27, 2026
    risk 0.65cvss epss 0.00

    ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in…

  • CVE-2026-18885CriAug 27, 2026
    risk 0.65cvss epss 0.00

    ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify,…

  • CVE-2026-0542CriFeb 25, 2026
    risk 0.60cvss epss 0.01

    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow Sandbox.    ServiceNow addressed…

  • CVE-2025-11450MedOct 10, 2025
    risk 0.34cvss epss 0.00

    ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link. …

  • CVE-2025-11449MedOct 10, 2025
    risk 0.34cvss epss 0.00

    ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link.    …

  • CVE-2025-3089MedAug 12, 2025
    risk 0.34cvss epss 0.00

    ServiceNow has addressed a Broken Access Control vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could allow a low privileged user to bypass access controls and perform a limited set of actions typically reserved for higher privileged users,…

  • CVE-2026-6875CriJul 13, 2026
    risk 0.02cvss epss 0.78

    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this…