Critical ServiceNow code execution flaw now exploited in attacks

A critical vulnerability in ServiceNow’s AI Platform has been exploited by attackers, highlighting the importance of prompt patching and security measures. The flaw, known as CVE-2026-6875, allows unauthenticated threat actors to execute code remotely within the platform.

ServiceNow’s AI Platform is a widely used enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate artificial intelligence into their core workflows. With over 100 billion workflows executed each year and powering more than 100,000 enterprise AI apps at 85% of all Fortune 500 companies, the platform’s security is paramount.

The vulnerability was discovered by cybersecurity company Searchlight Cyber in April and reported to ServiceNow. The company patched the flaw on July 13th, but it appears that attackers have already begun exploiting it in the wild. Threat intelligence firm Defused confirmed that in-the-wild exploitation of CVE-2026-6875 has been observed, with the first attempts spotted just days after ServiceNow issued patches.

The vulnerability allows threat actors to escape the sandbox and execute code remotely within the ServiceNow platform. This can lead to significant security breaches if left unaddressed. While ServiceNow has yet to flag this security as actively abused, the company advises all customers who have not already done so to secure their systems by upgrading to a patched release as soon as possible.

This incident serves as a reminder of the importance of timely patching and security measures. As seen in the case of CVE-2026-6875, even with patches available, attackers can still exploit vulnerabilities if they are not applied promptly. It is crucial for organizations to stay vigilant and prioritize security updates to prevent potential breaches.

For those affected by this vulnerability, it’s essential to act quickly to mitigate any potential damage. Upgrading to a patched release as soon as possible will help protect against exploitation attempts. Moreover, reviewing and strengthening security measures, such as access controls and monitoring, can further reduce the risk of successful attacks.

In conclusion, the exploitation of CVE-2026-6875 serves as a stark reminder that cybersecurity threats are constantly evolving. As organizations rely on complex systems like ServiceNow’s AI Platform to power their operations, it is crucial to prioritize security measures and stay ahead of potential threats. By doing so, businesses can minimize the risk of successful attacks and protect their sensitive data.


Source: Bleeping Computer — 2026-07-20