ServiceNow has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 8.7 (high), with 2 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.7
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Worst active — by depth score
CVE-2026-86860Critical· 9.3ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform51CVE-2026-13016Critical· 9.3ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform51CVE-2026-86859High· 8.7ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform48CVE-2026-86858High· 8.7ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform48CVE-2026-86857High· 8.4ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform46
ServiceNow vulnerabilities
CVEs affecting ServiceNow, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-86860Critical· 9.3ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform
ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what wa…
CVE-2026-86859High· 8.7ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform
ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform …
CVE-2026-86858High· 8.7ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform
ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete insta…
CVE-2026-13016Critical· 9.3ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform
ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the…
CVE-2026-86857High· 8.4ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform
ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform th…