PatchSiren

ServiceNow CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ServiceNow CVE published 2026-09-24

CVE-2026-86857

CVE-2026-86857 debrief based on the supplied source corpus. The CVE record was published on 2026-09-24T19:17:18.350Z and has not been modified since then. This authorization bypass issue in ServiceNow AI Platform could allow authenticated users to access unauthorized data. ServiceNow AI Platform administrators should assess exposure and apply updates to prevent potential data access. The CVE record and NV [truncated]

CRITICAL ServiceNow CVE published 2026-08-27

CVE-2026-74820

CVE-2026-74820 is a critical SQL injection vulnerability in the ServiceNow AI platform. This vulnerability allows an unauthenticated user to execute arbitrary SQL statements against the instance's underlying database, potentially leading to unauthorized data access or modification. ServiceNow has deployed security updates to hosted instances and provided updates to partners and self-hosted customers. The [truncated]

CRITICAL ServiceNow CVE published 2026-08-27

CVE-2026-6876

CVE-2026-6876 is a critical vulnerability in the ServiceNow AI Platform that allows an unauthenticated user to execute arbitrary code, potentially leading to increased access to the platform. This sandbox escape issue was identified and remediated by ServiceNow. The vulnerability has a CVSS score of 10 and a severity rating of CRITICAL. ServiceNow has deployed security updates to hosted instances and prov [truncated]

CRITICAL ServiceNow CVE published 2026-07-13

CVE-2026-6875

CVE-2026-6875 is a remote code execution vulnerability identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers an [truncated]

Known exploited ServiceNow CVE published 2024-07-29

CVE-2024-5217

CVE-2024-5217 is a ServiceNow Now Platform issue affecting Utah, Vancouver, and Washington DC releases and described as an incomplete list of disallowed inputs vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-29, which makes it a high-priority defensive item for organizations running the affected platform versions.

Known exploited ServiceNow CVE published 2024-07-29

CVE-2024-4879

CVE-2024-4879 is a ServiceNow Now Platform improper input validation issue that CISA added to its Known Exploited Vulnerabilities catalog on 2024-07-29. The supplied corpus identifies ServiceNow Utah, Vancouver, and Washington DC Now Platform as the affected product scope. Because it is in the KEV catalog, defenders should treat it as a high-priority remediation item and follow vendor guidance promptly.