Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User Impersonation

ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User Impersonation

Posted on January 13, 2026January 13, 2026 By CWS

Jan 13, 2026Ravie LakshmananVulnerability / SaaS Safety
ServiceNow has disclosed particulars of a now-patched important safety flaw impacting its ServiceNow AI Platform that might allow an unauthenticated consumer to impersonate one other consumer and carry out arbitrary actions as that consumer.
The vulnerability, tracked as CVE-2025-12420, carries a CVSS rating of 9.3 out of 10.0
“This challenge […] might allow an unauthenticated consumer to impersonate one other consumer and carry out the operations that the impersonated consumer is entitled to carry out,” the corporate stated in an advisory launched Monday.
The shortcoming was addressed by ServiceNow on October 30, 2025, by deploying a safety replace to the vast majority of hosted situations, with the corporate additionally sharing the patches with ServiceNow companions and self-hosted prospects.

The next variations embrace a repair for CVE-2025-12420 –

Now Help AI Brokers (sn_aia) – 5.1.18 or later and 5.2.19 or later
Digital Agent API (sn_va_as_service) – 3.15.2 or later and 4.0.4 or later

ServiceNow credited Aaron Costello, chief of SaaS Safety Analysis at AppOmni, with discovering and reporting the flaw in October 2025. Whereas there isn’t any proof that the vulnerability has been exploited within the wild, customers are suggested to use an applicable safety replace as quickly as potential to mitigate potential threats.
The disclosure comes almost two months after AppOmni revealed that malicious actors can exploit default configurations in ServiceNow’s Now Help generative synthetic intelligence (AI) platform and leverage its agentic capabilities to conduct second-order immediate injection assaults.
The difficulty might then be weaponized to execute unauthorized actions, enabling attackers to repeat and exfiltrate delicate company knowledge, modify data, and escalate privileges.

The Hacker News Tags:Allowing, Critical, Flaw, Impersonation, Patches, Platform, ServiceNow, Unauthenticated, User

Post navigation

Previous Post: Top 10 Best Practices for Securing Your Database
Next Post: Dutch Port Hacker Sentenced to Prison

Related Posts

U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware The Hacker News
SideCopy Shifts Focus to Indian Academia with ReverseRAT SideCopy Shifts Focus to Indian Academia with ReverseRAT The Hacker News
Critical Telnetd Security Flaw Allows Remote Code Execution Critical Telnetd Security Flaw Allows Remote Code Execution The Hacker News
Hackers Exploit Fake Resumes to Launch Crypto Miners Hackers Exploit Fake Resumes to Launch Crypto Miners The Hacker News
Critical Exploit Attempts on Super Forms and Elementor Pro Critical Exploit Attempts on Super Forms and Elementor Pro The Hacker News
DoJ Seizes 145 Domains Tied to BidenCash Carding Marketplace in Global Takedown DoJ Seizes 145 Domains Tied to BidenCash Carding Marketplace in Global Takedown The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark