Attackers are actively exploiting a critical vulnerability in the ServiceNow AI Platform. The flaw, tracked as CVE-2026-6875, allows unauthenticated attackers to remotely execute code. This vulnerability enables a full compromise of customer instances and connected systems.
Searchlight Cyber discovered and reported the security hole in April 2026. ServiceNow issued patches for self-hosted instances on July 13 and updated cloud platforms. Defused confirmed that exploitation attempts began just days after the patch release. Threat actors are utilizing a method distinct from the originally published proof-of-concept.