ServiceNow Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for ServiceNow products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

3

In CISA KEV

2

Beyond CISA KEV

1

Sensor Observed

1

Virtual Patch Available

0

ServiceNow KEVs Added by Year

Loading...

3 ServiceNow KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2026-6875

Sandbox Escape in ServiceNow AI Platform

Confirmed Not in CISA 18 Jul 2026
CVE-2024-4879

Jelly Template Injection Vulnerability in ServiceNow UI Macros

Confirmed In CISA 29 Jul 2024
CVE-2024-5217

Incomplete Input Validation in GlideExpression Script

Confirmed In CISA 29 Jul 2024

Common Vulnerability Classes (CWE)

  • CWE-1287 — Improper Validation of Specified Type of Input 1
  • CWE-184 — Incomplete List of Disallowed Inputs 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology