ServiceNow A.I CyberSecurity Scoring
ServiceNow
Company Information
Website:http://www.servicenow.com
Employees number:35,331
Number of followers:1,591,948
NAICS:5112
Industry Type:Software Development
Homepage:servicenow.com
ServiceNow Risk Score (AI oriented)
Between 800 and 849
ServiceNowSoftware Development
Updated:
13/08/2026
13/08/2026
813/1000
Good
A
ServiceNow Global Score (TPRM)
xxxx
ServiceNowSoftware Development
Score locked

ServiceNowGood
Current Score
813A (GOOD)
01000
7 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
816
Vulnerability
12 Aug 2026 • ServiceNow
ServiceNow, Salesforce and Contabo: "City-Forum" data-theft attacks target Salesforce, ServiceNow portals
Ongoing 'City-Forum' Data Theft Campaign Targets Misconfigured Salesforce and ServiceNow Portals
813
CRITICAL-3
SALSERCON1786602506
Ongoing "City-Forum" Data Theft Campaign Targets Misconfigured Salesforce and ServiceNow Portals
A persistent data theft campaign, tracked as City-Forum by SaaS security firm Reco, is exploiting misconfigured Salesforce Experience Cloud and ServiceNow customer portals to steal exposed data from organizations worldwide. The attacks, active since at least March 2025, originate from a single server (IP address 158.220.87.79, hosted by German VPS provider Contabo) and have targeted telecommunications firms, banks, enterprise software vendors, security companies, and public-sector entities.
Unlike traditional exploits, the campaign does not leverage vulnerabilities in Salesforce or ServiceNow. Instead, it abuses overly permissive guest-user configurations, allowing unauthenticated access to sensitive data. The attacker consistently uses the Go-http-client/1.1 user agent and the city-forum.com domain, which has resolved to the same infrastructure for over a year.
### Attack Methods
Salesforce Targets:
- The attacker primarily abuses the Aura framework, sending requests to `/aura` or `/s/sfsites/aura` endpoints to enumerate publicly accessible objects (e.g., Accounts, Contacts, Cases).
- Using `HostConfigController.getConfigData` and `SelectableListDataProviderController.getItems`, the attacker retrieves records from exposed objects. One victim recorded over 560,000 enumeration events from the attacker’s IP.
- The campaign also targets newer Lightning Web Runtime (LWR) sites, exploiting Salesforce’s UI API via GraphQL requests to `/webruntime/api/services/data/{version}/graphql` a technique not observed in public attack tools like AuraInspector or S-RET.
- Additional reconnaissance includes probing `/SiteRegister` and `/CommunitiesSelfReg` endpoints to check for self-registration, which could enable broader access.
ServiceNow Targets:
- The attacker abuses the POST `/api/now/sp/search` endpoint, designed for portal search functionality, to extract data from misconfigured search sources. While defenders can detect automated searches, ServiceNow’s logs do not record the exact search terms used.
- Activity has escalated from tens to hundreds of daily requests in some environments.
### Key Observations
- The campaign’s infrastructure has remained static since March 2025, unlike previous groups like ShinyHunters, which used multiple IPs.
- While some tactics resemble past ShinyHunters attacks (e.g., Aura endpoint abuse), Reco found no direct link between the two.
- All observed activity involves guest users, though authenticated access cannot be ruled out.
The attacks underscore the risks of misconfigured guest-user permissions in SaaS platforms, where even minor oversights can expose sensitive data to automated theft.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
815
Vulnerability
22 Jul 2026 • ServiceNow
Check Point: CISA Warns of Check Point Authentication Vulnerability Exploited in Attacks
Critical Check Point Authentication Flaw Actively Exploited in the Wild
812
CRITICAL-3
CHE1784787889
Critical Check Point Authentication Flaw Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about CVE-2026-16232, a critical authentication vulnerability in Check Point SmartConsole that is being actively exploited. The flaw, rated 9.3 on the CVSS scale, affects Check Point Security Management and Multi-Domain Management platforms, allowing unauthenticated remote attackers to obtain an application login token and gain full administrative access to affected systems.
The vulnerability was discovered during an internal BLAST (Business Logic Attack Surface Testing) review under Check Point’s Frontier AI Readiness Program. Exploitation has been confirmed in real-world attacks, though limited to environments where management interfaces are exposed to the internet without IP-based restrictions. Attackers could leverage this access to modify security policies, deploy malicious configurations, or pivot deeper into enterprise networks, risking full infrastructure compromise.
CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the need for immediate patching. Affected versions include R81.10, R81.20, R82, and R82.10, with older versions also potentially vulnerable. Check Point has released a Jumbo Hotfix (July 22, 2026) to remediate the issue and strengthen system resilience.
In the same advisory, Check Point disclosed two additional high-severity vulnerabilities:
- CVE-2026-62144 (CVSS 9.3): Another authentication bypass and privilege escalation flaw in management systems, though not yet exploited.
- CVE-2026-62145 (CVSS 7.5): A local privilege escalation issue in GaiaOS WebUI, currently unexploited.
Security teams are advised to restrict SmartConsole and management access to trusted IP addresses, enforce firewall protections, and monitor for indicators of compromise, including:
- 151.241.99[.]207
- 151.241.99[.]233
- 158.62.198[.]182
- 192.142.10[.]99
- 139.28.37[.]250
- 194.213.18[.]137
The incident underscores the risks of exposed management interfaces and the necessity of proactive patching, strict access controls, and continuous monitoring to mitigate evolving threats.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JULY 2026
818
Vulnerability
13 Jul 2026 • ServiceNow
ServiceNow: Critical ServiceNow Vulnerability Allows Remote Attackers to Execute Malicious Code
ServiceNow Patches Critical Sandbox Escape Vulnerability in AI Platform
815
CRITICAL-3
SER1784026078
ServiceNow Patches Critical Sandbox Escape Vulnerability in AI Platform
ServiceNow has addressed a severe security flaw (CVE-2026-6875) in its AI Platform that could allow unauthenticated attackers to execute arbitrary code on affected instances. The vulnerability, classified as a sandbox escape, impacts both hosted and self-hosted ServiceNow deployments, posing a significant risk to enterprises relying on the platform for IT service management, workflow automation, and business operations.
Exploitation of the flaw could enable threat actors to disrupt workflows, access or alter sensitive data, or use compromised environments as a foothold for further attacks. ServiceNow disclosed the issue on July 13, 2026, via advisory KB3137947, withholding technical details to prevent immediate exploitation while customers apply patches.
The company has already deployed fixes to its hosted instances and released updates for self-hosted environments. Specific patches vary by release:
- Brazil Early Access/General Availability: Fixed in current versions.
- Australia: Resolved in Australia Patch 2.
- Zurich: Mitigated in Patch 7b or Patch 9.
- Yokohama: Addressed in Patch 12 Hot Fix 1b or Patch 13.
ServiceNow reports no evidence of active exploitation but warns that public disclosure may attract malicious interest. Organizations are advised to verify their deployment type (hosted or self-hosted), confirm patch application, and monitor for unusual administrative activity, workflow changes, or API anomalies. Additional guidance is available in advisories KB2930717 and KB2930740.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
820
Vulnerability
05 Jun 2026 • ServiceNow
ServiceNow: ServiceNow discloses security incident exposing customer data
ServiceNow Warns of Exploited API Flaw Leading to Unauthorized Data Access
817
CRITICAL-3
SER1781072827
ServiceNow Warns of Exploited API Flaw Leading to Unauthorized Data Access
ServiceNow has disclosed a security incident involving the exploitation of an unauthenticated access flaw in a vulnerable API endpoint, allowing attackers to query data from customer instances. The company detected "anomalous activity" related to the issue and issued a security update on June 5, 2026, to hosted customer instances, restricting API access to authenticated users only.
The flaw, which could permit unauthorized access under certain conditions, was addressed by modifying the API endpoint configuration. While ServiceNow has not specified the exact data accessed, affected instances may store sensitive enterprise information, including IT support tickets, employee records, internal documentation, asset inventories, and security incident reports. Support tickets, in particular, are a prime target for threat actors, as they often contain credentials, API tokens, and authentication secrets.
ServiceNow has opened support cases with impacted customers, confirming that those without notifications are not believed to be affected. The issue primarily impacts customers on the Australia platform release or those running older releases with specific configuration changes.
Security researchers and administrators on Reddit identified the vulnerable endpoint as `/api/now/related_list_edit/create`, which was reportedly configured with `requires_authentication=false`. The update enforced authentication requirements. Indicators of compromise include API requests from the IP address `51.159.98.241`, and administrators are advised to review logs for suspicious activity.
ServiceNow has not yet disclosed whether a CVE will be assigned or provided further details on the duration of the exploitation. The company is still evaluating the incident’s scope and impact.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2026
818
APRIL 2026
820
MARCH 2026
821
FEBRUARY 2026
820
JANUARY 2026
822
Vulnerability
13 Jan 2026 • ServiceNow
ServiceNow: ServiceNow AI Vulnerability CVE-2025-12420: Critical Security Risk
ServiceNow AI Vulnerability CVE-2025-12420: Critical Security Risk
819
LOW-3
SER1768373239
Critical ServiceNow AI Vulnerability (CVE-2025-12420) Exposes Privilege Escalation Risk
On 13 January 2026, cybersecurity researchers disclosed CVE-2025-12420, a critical vulnerability in ServiceNow’s AI platform with a severity score of 9.3/10. The flaw, which could enable unauthenticated attackers to impersonate legitimate users, posed a severe risk of privilege escalation potentially allowing outsiders to access systems as privileged employees without credentials.
The vulnerability was first identified in October 2025 by SaaS security firm AppOmni, with researcher Aaron Costello contributing to its disclosure. ServiceNow responded swiftly, releasing security updates on 30 October 2025 to mitigate the threat for most hosted instances. However, self-hosted customers were urged to apply patches immediately, as the issue remained unaddressed in their environments.
The flaw specifically impacted two ServiceNow Store applications:
- Now Assist AI Agents (sn_aia) – Required updates to 5.1.18+ or 5.2.19+.
- Virtual Agent API (sn_va_as_service) – Required updates to 3.15.2+ or 4.0.4+.
While ServiceNow reported no known exploits at the time of disclosure, the company warned that publicly disclosed vulnerabilities heighten risk, emphasizing the need for affected customers to review the advisory. The incident underscores the growing security challenges in AI-driven enterprise platforms and the importance of rapid patching for both cloud and on-premises deployments.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JANUARY 2026
825
Vulnerability
06 Jan 2026 • ServiceNow
ServiceNow: Critical ServiceNow AI Platform Vulnerability Enables Remote Code Execution
Critical RCE Vulnerability Patched in ServiceNow AI Platform
822
CRITICAL-3
SER1772116716
Critical RCE Vulnerability Patched in ServiceNow AI Platform
A severe remote code execution (RCE) vulnerability, tracked as CVE-2026-0542, has been patched in ServiceNow’s enterprise AI platform. The flaw, rated Critical (CVSS 9.8), could allow unauthenticated attackers to execute malicious code on affected systems via remote network access, typically over HTTPS.
The vulnerability resides in the platform’s sandbox environment, designed to isolate untrusted code. Under specific conditions, exploitation could bypass these restrictions, leading to system compromise, data theft, or workflow manipulation. While ServiceNow has not disclosed technical details to prevent abuse, the flaw’s unauthenticated nature makes it a high-value target for threat actors.
ServiceNow addressed the issue by deploying security updates to hosted customer instances on January 6, 2026, with patches also released for self-hosted environments. As of the advisory’s release, the company reported no known active exploitation in the wild. However, organizations were urged to apply updates promptly.
Available patches by release:
- Zurich: Patch 4 Hotfix 3b (Feb 23, 2026), Patch 5 (Jan 12, 2026)
- Yokohama: Patch 10 Hotfix 1b (Feb 18, 2026), Patch 12 (Feb 6, 2026)
- Xanadu: Patch 11 Hotfix 1a (Feb 2, 2026)
- Australia: Pending fix (expected Q2 2026)
Customers enrolled in the January Patching Program were automatically updated. ServiceNow’s advisory (KB2693566) provides further details for affected users.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
831
NOVEMBER 2025
831
OCTOBER 2025
831
SEPTEMBER 2025
831
FEBRUARY 2025
830
Vulnerability
01 Feb 2025 • ServiceNow
ServiceNow
Count(er) Strike Vulnerability in ServiceNow
830
CRITICAL0
SER543070925
A new vulnerability in ServiceNow, dubbed Count(er) Strike, allows low-privileged users to extract sensitive data from tables to which they should not have access. The flaw, discovered by Varonis Threat Labs in February 2025 and assigned the CVE-2025-3648 identifier, impacts configurations with misconfigured or overly permissive ACLs. This vulnerability could lead to the leakage of sensitive data, including credentials, PII, and internal configuration data, potentially affecting various industries using ServiceNow, such as public sector organizations, healthcare, financial institutions, and large enterprises.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for ServiceNow ??
What was ServiceNow's A.I Rankiteo Cyber Score in July 2026 ??
What was ServiceNow's A.I Rankiteo Cyber Score in June 2026 ??
What was ServiceNow's A.I Rankiteo Cyber Score in May 2026 ??
What was ServiceNow's A.I Rankiteo Cyber Score in April 2026 ??
What was ServiceNow's A.I Rankiteo Cyber Score in March 2026 ??
What was ServiceNow's A.I Rankiteo Cyber Score in February 2026 ??
What was ServiceNow's A.I Rankiteo Cyber Score in January 2026 ??
What was ServiceNow's A.I Rankiteo Cyber Score in December 2025 ??
What was ServiceNow's A.I Rankiteo Cyber Score in November 2025 ??
What was ServiceNow's A.I Rankiteo Cyber Score in October 2025 ??
What was ServiceNow's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on ServiceNow's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with ServiceNow ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view ServiceNow's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?