Critical ServiceNow code execution flaw now exploited in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. The flaw allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow pl…
Intelligence analysis by Llama

A critical vulnerability in the ServiceNow AI Platform has been exploited in the wild, allowing attackers to execute code remotely within the platform. ServiceNow has released patches for the flaw, but attackers have already begun exploiting it.
Imagine you have a super powerful computer that can do lots of things for you, like a virtual assistant. But, someone found a way to hack into that computer and do bad things, like steal your information or mess up your system. This is what happened with the ServiceNow AI Platform, a computer system that helps businesses work with artificial intelligence. Someone found a way to hack into it and do bad things, and now businesses need to fix it to keep their information safe.
Analysis
A Critical Flaw in the ServiceNow AI Platform
The ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows. However, a critical vulnerability (CVE-2026-6875) in the platform has been exploited in the wild, allowing attackers to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks.
The flaw was first reported by cybersecurity company Searchlight Cyber on April 1st and was patched by ServiceNow across hosted instances and released CVE-2026-6875 security updates for self-hosted instances on July 13th. However, threat intelligence company Defused has confirmed that attackers have begun exploiting the vulnerability in the wild, with the first attempts being observed on Friday, days after ServiceNow issued patches.
ServiceNow has yet to flag this security as actively abused and, in the official advisory, still states that it is 'not currently aware of exploitation against ServiceNow instances.' However, the company advises all customers who have not already done so to secure their systems against attacks by upgrading to a patched release as soon as possible.
The Impact of the Flaw
The critical vulnerability in the ServiceNow AI Platform has significant implications for businesses that rely on the platform for their AI workflows. The flaw allows attackers to execute code remotely within the platform, which can lead to a range of malicious activities, including data theft and system compromise.
The Importance of Patching Vulnerabilities
The exploitation of the ServiceNow AI Platform vulnerability highlights the importance of patching vulnerabilities in enterprise software to prevent exploitation by attackers. Businesses that rely on the platform for their AI workflows should take immediate action to patch the flaw and secure their systems against attacks.
Conclusion
The critical vulnerability in the ServiceNow AI Platform is a significant security risk that businesses should take seriously. The exploitation of the flaw highlights the importance of patching vulnerabilities in enterprise software to prevent exploitation by attackers. Businesses that rely on the platform for their AI workflows should take immediate action to patch the flaw and secure their systems against attacks.
Key points
- A critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform has been exploited in the wild, allowing attackers to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks.
- ServiceNow has released patches for the flaw, but attackers have already begun exploiting it.
- The flaw allows attackers to execute code remotely within the platform, which can lead to a range of malicious activities, including data theft and system compromise.
- Businesses that rely on the platform for their AI workflows should take immediate action to patch the flaw and secure their systems against attacks.
ServiceNow has already released patches for the flaw, and businesses that rely on the platform for their AI workflows should take immediate action to patch the flaw and secure their systems against attacks. This should help prevent further exploitation of the vulnerability and keep businesses' information safe.
The exploitation of the ServiceNow AI Platform vulnerability highlights the importance of patching vulnerabilities in enterprise software to prevent exploitation by attackers. If businesses do not take immediate action to patch the flaw and secure their systems against attacks, they may be at risk of further exploitation, which could lead to data theft and system compromise.


