CVE Tools

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

The Hacker NewsBy The Hacker News

Reported exploitedServiceNow AI Platform

Our summary

A critical vulnerability in ServiceNow AI Platform, identified as CVE-2026-6875, is currently being actively exploited by attackers to execute arbitrary code without authentication. The flaw, rated with a CVSS score of 9.5, enables sandbox escape and has been observed in real-world attacks targeting the "/assessment_thanks.do" endpoint. Patches have been issued for several versions including Brazil EA/GA, Australia Patch 2, Zurich Patch 7b/9, and Yokohama Patch 12 Hot Fix 1b/Patch 13. Security researchers emphasize the need for immediate patching to prevent full system compromise.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store