Critical ServiceNow Remote Code Execution Flaw Under Active Attack

Threat researchers at Defused confirm that attackers are now actively exploiting a critical vulnerability in the ServiceNow AI Platform, known as CVE-2026-6875. The flaw allows unauthenticated threat actors to escape the platform's sandbox and execute malicious code remotely. Searchlight Cyber originally discovered and reported the vulnerability in April, and ServiceNow released patches for all instances on July 13th. The first exploitation attempts appeared just days after those patches became available.

Despite evidence of active attacks in the wild, ServiceNow has not yet updated its official advisory to reflect the ongoing threat. The company still states that it is unaware of any exploitation targeting its instances. Security experts warn that organizations running self-hosted deployments remain especially at risk if they have not yet applied the available security updates. The attacks use a slightly different technique than the original proof of concept but reach the same dangerous code execution capability.

This incident follows a separate security event last month in which attackers accessed customer data through a vulnerable API endpoint. ServiceNow attributed that earlier breach to security research activity rather than malicious actors. With the platform processing over 100 billion workflows annually across tens of thousands of enterprise applications, the urgency for customers to patch their systems cannot be overstated. Administrators are strongly encouraged to upgrade to a patched release immediately.

Read More at the original source →