Critical ServiceNow code execution flaw now exploited in attacks
Reported exploitedServiceNow AI PlatformOur summary
A critical vulnerability in ServiceNow's AI Platform, CVE-2026-6875, is now being actively exploited by attackers, according to threat intelligence firm Defused. The flaw allows unauthenticated users to break out of a sandbox and execute arbitrary code remotely. Despite patches being issued on July 13, real-world attacks were detected just days later. ServiceNow urges all users to apply the latest security updates immediately.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.