CVE Tools

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

SecurityWeekBy Eduard Kovacs

Reported exploitedServiceNow AI platform

Our summary

A critical remote code execution vulnerability in ServiceNow's AI platform, tracked as CVE-2026-6875, is being actively exploited just days after its disclosure. The flaw allows unauthenticated attackers to bypass sandbox protections and execute arbitrary code under specific conditions. While ServiceNow has deployed patches for hosted instances, self-hosted customers are responsible for applying them. Cybersecurity firm Searchlight Cyber published technical details on July 14, followed by reports from Defused indicating real-world exploitation using those methods. Although ServiceNow initially stated it had no evidence of active attacks, a spokesperson confirmed awareness of the exploitation but noted it appears limited to non-hosted environments.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store