Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Reported exploitedServiceNow AI PlatformOur summary
A critical vulnerability in ServiceNow AI Platform, identified as CVE-2026-6875, is currently being actively exploited by attackers to execute arbitrary code without authentication. The flaw, rated with a CVSS score of 9.5, enables sandbox escape and has been observed in real-world attacks targeting the "/assessment_thanks.do" endpoint. Patches have been issued for several versions including Brazil EA/GA, Australia Patch 2, Zurich Patch 7b/9, and Yokohama Patch 12 Hot Fix 1b/Patch 13. Security researchers emphasize the need for immediate patching to prevent full system compromise.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.