Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
ServiceNow

ServiceNow Vendor Cyber Rating & Cyber Score

servicenow.com

ServiceNow (NYSE: NOW) makes the world work better for everyone. Our cloud-based platform and solutions help digitize and unify organizations so that they can find smarter, faster, better ways to make work flow. So employees and customers can be more connected, more innovative, and more agile. And we can all create the future we imagine. The world works with ServiceNow. For more information, visit www.servicenow.com.


ServiceNow A.I CyberSecurity Scoring

ServiceNow
Company Information
Website:http://www.servicenow.com
Employees number:31,971
Number of followers:1,427,126
NAICS:5112
Industry Type:Software Development
Homepage:servicenow.com
ServiceNow Risk Score (AI oriented)
Between 800 and 849
logo
ServiceNowSoftware Development
Updated:
10/06/2026
819/1000
Good
A
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
ServiceNow Global Score (TPRM)
xxxx
logo
ServiceNowSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

ServiceNow
ServiceNowGood
Current Score
819A (GOOD)
01000
4 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
820Before Incident
Vulnerability
05 Jun 2026ServiceNow
ServiceNow: ServiceNow discloses security incident exposing customer data

ServiceNow Warns of Exploited API Flaw Leading to Unauthorized Data Access

817After Incident
CRITICAL-3
SER1781072827
ServiceNow Warns of Exploited API Flaw Leading to Unauthorized Data Access ServiceNow has disclosed a security incident involving the exploitation of an unauthenticated access flaw in a vulnerable API endpoint, allowing attackers to query data from customer instances. The company detected "anomalous activity" related to the issue and issued a security update on June 5, 2026, to hosted customer instances, restricting API access to authenticated users only. The flaw, which could permit unauthorized access under certain conditions, was addressed by modifying the API endpoint configuration. While ServiceNow has not specified the exact data accessed, affected instances may store sensitive enterprise information, including IT support tickets, employee records, internal documentation, asset inventories, and security incident reports. Support tickets, in particular, are a prime target for threat actors, as they often contain credentials, API tokens, and authentication secrets. ServiceNow has opened support cases with impacted customers, confirming that those without notifications are not believed to be affected. The issue primarily impacts customers on the Australia platform release or those running older releases with specific configuration changes. Security researchers and administrators on Reddit identified the vulnerable endpoint as `/api/now/related_list_edit/create`, which was reportedly configured with `requires_authentication=false`. The update enforced authentication requirements. Indicators of compromise include API requests from the IP address `51.159.98.241`, and administrators are advised to review logs for suspicious activity. ServiceNow has not yet disclosed whether a CVE will be assigned or provided further details on the duration of the exploitation. The company is still evaluating the incident’s scope and impact.
INCIDENT DETAILS -
TYPE
Unauthorized Data Access
IMPACT
Data Compromised: Sensitive enterprise information, including IT support tickets, employee records, internal documentation, asset inventories, and security incident reportsSystems Affected: Customer instances on the Australia platform release or older releases with specific configuration changesIdentity Theft Risk: Potential risk due to exposure of credentials, API tokens, and authentication secrets
DATA BREACH
IT support ticketsEmployee recordsInternal documentationAsset inventoriesSecurity incident reportsSensitivity Of Data: High (credentials, API tokens, authentication secrets)Personally Identifiable Information: Potential (credentials, API tokens, authentication secrets)
MAY 2026
818Before Incident
APRIL 2026
820Before Incident
MARCH 2026
821Before Incident
FEBRUARY 2026
820Before Incident
JANUARY 2026
822Before Incident
Vulnerability
13 Jan 2026ServiceNow
ServiceNow: ServiceNow AI Vulnerability CVE-2025-12420: Critical Security Risk

ServiceNow AI Vulnerability CVE-2025-12420: Critical Security Risk

819After Incident
LOW-3
SER1768373239
Critical ServiceNow AI Vulnerability (CVE-2025-12420) Exposes Privilege Escalation Risk On 13 January 2026, cybersecurity researchers disclosed CVE-2025-12420, a critical vulnerability in ServiceNow’s AI platform with a severity score of 9.3/10. The flaw, which could enable unauthenticated attackers to impersonate legitimate users, posed a severe risk of privilege escalation potentially allowing outsiders to access systems as privileged employees without credentials. The vulnerability was first identified in October 2025 by SaaS security firm AppOmni, with researcher Aaron Costello contributing to its disclosure. ServiceNow responded swiftly, releasing security updates on 30 October 2025 to mitigate the threat for most hosted instances. However, self-hosted customers were urged to apply patches immediately, as the issue remained unaddressed in their environments. The flaw specifically impacted two ServiceNow Store applications: - Now Assist AI Agents (sn_aia) – Required updates to 5.1.18+ or 5.2.19+. - Virtual Agent API (sn_va_as_service) – Required updates to 3.15.2+ or 4.0.4+. While ServiceNow reported no known exploits at the time of disclosure, the company warned that publicly disclosed vulnerabilities heighten risk, emphasizing the need for affected customers to review the advisory. The incident underscores the growing security challenges in AI-driven enterprise platforms and the importance of rapid patching for both cloud and on-premises deployments.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Systems Affected: ServiceNow AI platform (Now Assist AI Agents, Virtual Agent API)Identity Theft Risk: High (impersonation of privileged users)
JANUARY 2026
825Before Incident
Vulnerability
06 Jan 2026ServiceNow
ServiceNow: Critical ServiceNow AI Platform Vulnerability Enables Remote Code Execution

Critical RCE Vulnerability Patched in ServiceNow AI Platform

822After Incident
CRITICAL-3
SER1772116716
Critical RCE Vulnerability Patched in ServiceNow AI Platform A severe remote code execution (RCE) vulnerability, tracked as CVE-2026-0542, has been patched in ServiceNow’s enterprise AI platform. The flaw, rated Critical (CVSS 9.8), could allow unauthenticated attackers to execute malicious code on affected systems via remote network access, typically over HTTPS. The vulnerability resides in the platform’s sandbox environment, designed to isolate untrusted code. Under specific conditions, exploitation could bypass these restrictions, leading to system compromise, data theft, or workflow manipulation. While ServiceNow has not disclosed technical details to prevent abuse, the flaw’s unauthenticated nature makes it a high-value target for threat actors. ServiceNow addressed the issue by deploying security updates to hosted customer instances on January 6, 2026, with patches also released for self-hosted environments. As of the advisory’s release, the company reported no known active exploitation in the wild. However, organizations were urged to apply updates promptly. Available patches by release: - Zurich: Patch 4 Hotfix 3b (Feb 23, 2026), Patch 5 (Jan 12, 2026) - Yokohama: Patch 10 Hotfix 1b (Feb 18, 2026), Patch 12 (Feb 6, 2026) - Xanadu: Patch 11 Hotfix 1a (Feb 2, 2026) - Australia: Pending fix (expected Q2 2026) Customers enrolled in the January Patching Program were automatically updated. ServiceNow’s advisory (KB2693566) provides further details for affected users.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: Potential data theftSystems Affected: ServiceNow AI platform sandbox environmentOperational Impact: Workflow manipulation
DATA BREACH
Data Exfiltration: Potential data theft
DECEMBER 2025
831Before Incident
NOVEMBER 2025
831Before Incident
OCTOBER 2025
831Before Incident
SEPTEMBER 2025
831Before Incident
AUGUST 2025
831Before Incident
JULY 2025
831Before Incident
FEBRUARY 2025
830Before Incident
Vulnerability
01 Feb 2025ServiceNow
ServiceNow

Count(er) Strike Vulnerability in ServiceNow

830After Incident
CRITICAL0
SER543070925
A new vulnerability in ServiceNow, dubbed Count(er) Strike, allows low-privileged users to extract sensitive data from tables to which they should not have access. The flaw, discovered by Varonis Threat Labs in February 2025 and assigned the CVE-2025-3648 identifier, impacts configurations with misconfigured or overly permissive ACLs. This vulnerability could lead to the leakage of sensitive data, including credentials, PII, and internal configuration data, potentially affecting various industries using ServiceNow, such as public sector organizations, healthcare, financial institutions, and large enterprises.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
MOTIVATION
Data Exfiltration
IMPACT
Data Compromised: Sensitive data, credentials, PII, internal configuration dataSystems Affected: ServiceNow ITSM product and potentially all ServiceNow products utilizing the same ACL logic
DATA BREACH
Type Of Data Compromised: Sensitive data, credentials, PII, internal configuration dataData Exfiltration: Enumeration of data records from a tablePersonally Identifiable Information: PII

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for ServiceNow ?
?
What was ServiceNow's A.I Rankiteo Cyber Score in May 2026 ?
?
What was ServiceNow's A.I Rankiteo Cyber Score in April 2026 ?
?
What was ServiceNow's A.I Rankiteo Cyber Score in March 2026 ?
?
What was ServiceNow's A.I Rankiteo Cyber Score in February 2026 ?
?
What was ServiceNow's A.I Rankiteo Cyber Score in January 2026 ?
?
What was ServiceNow's A.I Rankiteo Cyber Score in December 2025 ?
?
What was ServiceNow's A.I Rankiteo Cyber Score in November 2025 ?
?
What was ServiceNow's A.I Rankiteo Cyber Score in October 2025 ?
?
What was ServiceNow's A.I Rankiteo Cyber Score in September 2025 ?
?
What was ServiceNow's A.I Rankiteo Cyber Score in August 2025 ?
?
What was ServiceNow's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on ServiceNow's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with ServiceNow ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view ServiceNow's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?