A Critical Vulnerability in ServiceNow’s AI Platform is Being Exploited by Attackers
A critical vulnerability in the ServiceNow AI Platform, a popular enterprise-grade platform that helps businesses integrate artificial intelligence into core workflows, has been discovered to be actively exploited by attackers. The vulnerability, known as CVE-2026-6875, allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform.
The flaw was first reported in April by cybersecurity company Searchlight Cyber, which found that it could be exploited to gain remote code execution capabilities. Despite ServiceNow’s efforts to address the issue across hosted instances starting in April, self-hosted instances were only provided with security updates last week on July 13th. Unfortunately, this delay has given attackers a window of opportunity to exploit the vulnerability.
Threat intelligence company Defused recently confirmed that attackers have begun exploiting the vulnerability in the wild, with the first attempts being observed on Friday. According to Defused, the payloads used to exploit the flaw are hitting the same pre-auth sink that was documented by Searchlight Cyber, but the sandbox-escape gadget is reaching the same code-execution primitive via a different route.
ServiceNow has acknowledged the exploitation of the vulnerability and advises all customers who have not already done so to secure their systems against attacks by upgrading to a patched release as soon as possible. The company claims that it is not currently aware of any instances being exploited, but this may be due to the fact that the company’s monitoring capabilities are limited to hosted instances.
The ServiceNow AI Platform is widely used by enterprises, with over 100 billion workflows executed each year and powering more than 100,000 enterprise AI apps at 85% of all Fortune 500 companies. The exploitation of this vulnerability highlights the importance of staying up-to-date with security patches and updates, especially for critical systems that are vulnerable to remote code execution attacks.
While ServiceNow’s efforts to address the issue are commendable, it is clear that more needs to be done to prevent such vulnerabilities from being exploited in the first place. As we have seen time and time again, even the most well-intentioned companies can fall victim to exploitation when their systems are not properly secured.
So what can you do to protect yourself? The takeaway here is simple: test every layer of your security before attackers do. This means regularly conducting breach and attack simulation tests on your SIEM and EDR rules to ensure that they are working as intended. By doing so, you can identify vulnerabilities and fix them before they are exploited by attackers. It’s a lesson that ServiceNow would do well to take to heart in the coming days and weeks ahead.
Source: Bleeping Computer — 2026-07-20