ServiceNow Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for ServiceNow products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
3
In CISA KEV
2
Beyond CISA KEV
1
Sensor Observed
1
Virtual Patch Available
0
ServiceNow KEVs Added by Year
Loading...
3 ServiceNow KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-6875
Sandbox Escape in ServiceNow AI Platform |
ServiceNow AI Platform | Confirmed | Not in CISA | 18 Jul 2026 |
|
CVE-2024-4879
Jelly Template Injection Vulnerability in ServiceNow UI Macros |
Now Platform | Confirmed | In CISA | 29 Jul 2024 |
|
CVE-2024-5217
Incomplete Input Validation in GlideExpression Script |
Now Platform | Confirmed | In CISA | 29 Jul 2024 |
Common Vulnerability Classes (CWE)
- CWE-1287 — Improper Validation of Specified Type of Input 1
- CWE-184 — Incomplete List of Disallowed Inputs 1
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology