Servicenow
Servicenow AI Platform: vulnerabilidades y CVE
Servicenow AI Platform tiene 12 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses11
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86860 | Crítica (9.3) | 0.30% | — | 24 sept 2026 | ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance… |
| CVE-2026-86859 | Alta (8.7) | 0.29% | — | 24 sept 2026 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the… |
| CVE-2026-86858 | Alta (8.7) | 0.27% | — | 24 sept 2026 | ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create,… |
| CVE-2026-86857 | Alta (8.4) | 0.24% | — | 24 sept 2026 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the… |
| CVE-2026-6876 | Crítica (10) | 0.62% | — | 27 ago 2026 | ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI… |
| CVE-2026-18886 | Crítica (10) | 5.0% | — | 27 ago 2026 | ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or… |
| CVE-2026-18885 | Crítica (10) | 7.2% | — | 27 ago 2026 | ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in… |
| CVE-2026-6875 | Crítica (9.5) | 1.4% | — | 13 jul 2026 | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within… |
| CVE-2026-0542 | Crítica (9.2) | 0.59% | — | 25 feb 2026 | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within… |
| CVE-2025-11450 | Media (5.3) | 0.36% | — | 10 oct 2025 | ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of… |
| CVE-2025-11449 | Media (5.3) | 0.36% | — | 10 oct 2025 | ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of… |
| CVE-2025-3089 | Media (5.3) | 0.35% | — | 12 ago 2025 | ServiceNow has addressed a Broken Access Control vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could allow a low privileged user to bypass access controls and perform a limited set… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.