Threat researchers at Defused confirm that attackers are now actively exploiting a critical vulnerability in the ServiceNow AI Platform, known as CVE-2026-6875. The flaw allows unauthenticated threat actors to escape the platform's sandbox and execute malicious code remotely. Searchlight Cyber originally discovered and reported the vulnerability in April,