ServiceNow
ServiceNow AI Platform
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-86860 | 24 Sep 2026 | ServiceNow AI Platform: < Yokohama Patch 13 Hot Fix 5a, < Zurich Patch 10 Hot Fix 3b, < Zurich Patch 10 Hot Fix 4a W32, < Zurich Patch 11 Hot Fix 3, < Australia Patch 2 Hot Fix 4b W32, < Australia Patch 4 Hot Fix 3, < Australia Patch 5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-86859 | 24 Sep 2026 | ServiceNow AI Platform: < Yokohama Patch 13 Hot Fix 5a, < Zurich Patch 10 Hot Fix 3b, < Zurich Patch 10 Hot Fix 4a W32, < Zurich Patch 11 Hot Fix 3, < Australia Patch 2 Hot Fix 4b W32, < Australia Patch 4 Hot Fix 3, < Australia Patch 5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-13016 | 24 Sep 2026 | ServiceNow AI Platform: < Yokohama Patch 13 Hot Fix 5a, < Zurich Patch 10 Hot Fix 3b, < Zurich Patch 10 Hot Fix 4a W32, < Zurich Patch 11 Hot Fix 3, < Australia Patch 2 Hot Fix 4b W32, < Australia Patch 4 Hot Fix 3, < Australia Patch 5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-86858 | 24 Sep 2026 | ServiceNow AI Platform: < Yokohama Patch 13 Hot Fix 5a, < Zurich Patch 10 Hot Fix 3b, < Zurich Patch 10 Hot Fix 4a W32, < Zurich Patch 11 Hot Fix 3, < Australia Patch 2 Hot Fix 4b W32, < Australia Patch 4 Hot Fix 3, < Australia Patch 5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-86857 | 24 Sep 2026 | ServiceNow AI Platform: < Yokohama Patch 13 Hot Fix 5a, < Zurich Patch 10 Hot Fix 3b, < Zurich Patch 10 Hot Fix 4a W32, < Zurich Patch 11 Hot Fix 3, < Australia Patch 2 Hot Fix 4b W32, < Australia Patch 4 Hot Fix 3, < Australia Patch 5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-74820 | 27 Aug 2026 | < Xanadu Patch 11 Hot Fix 7a; < Yokohama Patch 12 Hot Fix 3b; < Yokohama Patch 13 Hot Fix 4; < Zurich Patch 7b Hot Fix 3; < Zurich Patch 8 Hot Fix 5; < Zurich Patch 9 Hot Fix 6; < Zurich Patch 10 Hot Fix 2m (m-branch); < Zurich Patch 10 Hot Fix 3 (standard) | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-18886 | 27 Aug 2026 | ServiceNow AI Platform: < Xanadu Patch 11 Hot Fix 7a, < Yokohama Patch 12 Hot Fix 3b, < Yokohama Patch 13 Hot Fix 4, < Zurich Patch 7b Hot Fix 3, < Zurich Patch 8 Hot Fix 5, < Zurich Patch 9 Hot Fix 6, < Zurich Patch 10 Hot Fix 2m (m-branch), < Zurich Patch 10 Hot Fix 3 (standard), < Zurich Patch 11, < Zurich Patch 12, < Australia Patch 2 Hot Fix 3, < Australia Patch 3 Hot Fix 2, < Australia Patch 3m, < Australia Patch 4, < Australia Patch 5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-18885 | 27 Aug 2026 | < Xanadu Patch 11 Hot Fix 7a; < Yokohama Patch 12 Hot Fix 3b; < Yokohama Patch 13 Hot Fix 4; < Zurich Patch 7b Hot Fix 3; < Zurich Patch 8 Hot Fix 5; < Zurich Patch 9 Hot Fix 6; < Zurich Patch 10 Hot Fix 2m (m-branch); < Zurich Patch 10 Hot Fix 3 (standard) | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-6876 | 27 Aug 2026 | ServiceNow AI Platform: < Xanadu Patch 11 Hot Fix 7a, < Yokohama Patch 12 Hot Fix 3b, < Yokohama Patch 13 Hot Fix 4, < Zurich Patch 7b Hot Fix 3, < Zurich Patch 8 Hot Fix 5, < Zurich Patch 9 Hot Fix 6, < Zurich Patch 10 Hot Fix 2m (m-branch), < Zurich Patch 10 Hot Fix 3 (standard), < Zurich Patch 11, < Zurich Patch 12, < Australia Patch 2 Hot Fix 3, < Australia Patch 3 Hot Fix 2, < Australia Patch 3m, < Australia Patch 4, < Australia Patch 5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2026-6875 | 13 Jul 2026 | < Australia Patch 2; < Yokohama Patch 12 Hot Fix 1b; < Yokohama Patch 13; < Zurich Patch 7b; < Zurich Patch 9; < Brazil EA; < Brazil GA | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2026-0542 | 25 Feb 2026 | < Australia; < Zurich Patch 5; < Zurich Patch 4 Hot Fix 3b; < Yokohama Patch 12; < Yokohama Patch 10 Hot Fix 1b; < Xanadu Patch 11 Hot Fix 1a | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2025-11449 | 10 Oct 2025 | ServiceNow AI Platform: < Washington DC Patch 10 Hot Fix 7b, < Xanadu Patch 10 Hot Fix 1a, < Xanadu Patch 11, < Yokohama Patch 7 Hot Fix 2a, < Yokohama Patch 8, < Yokohama Patch 9, < Zurich Patch 1 Hot Fix 1a, < Zurich Patch 2, < Zurich Patch 3, < Australia General Availability (GA) | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2025-11450 | 10 Oct 2025 | ServiceNow AI Platform: < Washington DC Patch 10 Hot Fix 7b, < Xanadu Patch 10 Hot Fix 1a, < Xanadu Patch 11, < Yokohama Patch 7 Hot Fix 2a, < Yokohama Patch 8, < Yokohama Patch 9, < Zurich Patch 1 Hot Fix 1a, < Zurich Patch 2, < Zurich Patch 3, < Australia General Availability (GA) | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2025-3089 | 12 Aug 2025 | Aspen < Washington DC Patch 10 Hot Fix 2a; Aspen < Xanadu Patch 7a; Aspen < Xanadu Patch 8; Aspen < Yokohama Patch 1a; Aspen < Yokohama Patch 2; Aspen < Zurich (EA) | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.