Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Cybersecurity is about sharing. Recognize the risk,
combat it, share your experiences, and encourage others
to do better than you.
Select language
Banner Ransomfeed 320x100 1
LECS 970x120 1
ServiceNow AI Vulnerability CVE-2025-12420: Critical Security Risk

ServiceNow AI Vulnerability CVE-2025-12420: Critical Security Risk

13 January 2026 07:26

A critical flaw has been identified in ServiceNow’s artificial intelligence platform, with a severity score of 9.3 out of 10. This vulnerability, classified as CVE-2025-12420, could allow attackers to impersonate legitimate users without authenticating.

ServiceNow has already implemented rapid remediation measures for most hosted instances, but the issue remains a significant risk of privilege escalation. Imagine an outsider impersonating a privileged employee without ever logging in: this is the scenario CVE-2025-12420 threatened to bring to fruition.

ServiceNow moved quickly to contain the threat. On October 30, 2025, the company released security updates that addressed the vulnerability for most of its hosted environment.

The vulnerability was brought to light in October 2025 by SaaS security firm AppOmni ; researcher Aaron Costello is also credited for his assistance in the disclosure process.

According to ServiceNow,At this time, ServiceNow is not aware of any instances of this issue being exploited against customer instances.” However, the company cautions that ” due to the potential increased risk when vulnerabilities are publicly disclosed, we recommend hosted and self-hosted customers read this advisory carefully.”

While hosted instances have been largely patched, customers and partners running self-hosted instances should take immediate action to ensure the security of their networks. The vulnerability affects specific Store applications, and updates have been released for:

  • Now Assist AI Agents (sn_aia): Update to version 5.1.18 or later, or 5.2.19 or later.
  • Virtual Agent API (sn_va_as_service): Please update to version 3.15.2 or later, or 4.0.4 or later.

Follow us on Google News to receive daily updates on cybersecurity. Contact us if you would like to report news, insights or content for publication.

Cropped RHC 3d Transp2 1766828557 300x300
The editorial staff of Red Hot Cyber is composed of IT and cybersecurity professionals, supported by a network of qualified sources who also operate confidentially. The team works daily to analyze, verify, and publish news, insights, and reports on cybersecurity, technology, and digital threats, with a particular focus on the accuracy of information and the protection of sources. The information published is derived from direct research, field experience, and exclusive contributions from national and international operational contexts.