ServiceNow Vulnerabilities and Affected Products
Vulnerabilities associated with Virtual Agent API.
Products
Clear product- Now Platform11 vulnerabilities
- servicenow5 vulnerabilities
- ServiceNow AI Platform5 vulnerabilities
- Jenkins plug-in for ServiceNow DevOps2 vulnerabilities
- Utah, Vancouver, and Washington DC Now Platform2 vulnerabilities
- Now Assist AI Agents1 vulnerability
- Now User Experience1 vulnerability
- ServiceNow Records1 vulnerability
- Virtual Agent API1 vulnerability
- Washington DC, Vancouver, and Utah Now Platform1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-12420CRITICAL | Unauthenticated Privilege Escalation in ServiceNow AI PlatformA vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a relevant security update to hosted instances in October 2025. Security updates have also been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Additionally, the vulnerab… | CVSS9.3v4.0 | EPSS46.1% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |