🔴 Critical  |  Source: The Hacker News


A critical vulnerability in the ServiceNow AI Platform (CVE-2026-6875, CVSS 9.5) is being actively exploited in the wild, allowing unauthenticated attackers to escape the application sandbox and execute arbitrary code. The flaw requires no credentials, significantly lowering the bar for attackers. Patches have been released, but active exploitation means organisations running ServiceNow are at immediate risk.

Security Architect’s Take: Prioritise patching CVE-2026-6875 across all ServiceNow instances immediately — active exploitation with no authentication requirement means exposure windows must be minimised to hours, not days. If patching cannot be applied immediately, consider restricting network access to ServiceNow instances to known IP ranges and review logs for anomalous unauthenticated activity.

Original advisory: Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution