Skip to content

ServiceNow AI Platform: Critical Vulnerability CVE-2026-6875 Actively Exploited

The Bottom Line: CVE-2026-6875 in the ServiceNow AI Platform is actively exploited and enables unauthenticated code execution through a sandbox escape.

A critical security vulnerability in the ServiceNow AI Platform is already being exploited in the wild. The vulnerability CVE-2026-6875 allows attackers without authentication to execute arbitrary code.

Threat intelligence firm Defused Cyber is observing active attacks against the ServiceNow AI Platform exploiting vulnerability CVE-2026-6875. The flaw carries a CVSS score of 9.5 and allows unauthenticated users to execute arbitrary code through a sandbox escape.

For CISOs, this active exploitation in the wild represents a high immediate risk for organizations using ServiceNow AI capabilities. The absence of authentication as a prerequisite significantly lowers the barrier to entry for attackers.

ServiceNow has released patches for the security flaw. It is recommended to deploy these immediately and review existing ServiceNow AI Platform deployments for signs of compromise.


Source: thehackernews.com · Published 21 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.

Share on: