Vulnerabilities & Exploits · Zero-Day Exploit

Lagging ServiceNow Instances Stay Exposed After Patch Rollout

The risk shifted from a vendor fix notice to live exposure on any ServiceNow AI Platform instance that has not yet taken the update. Hosted tenants were already updated, but unpatched or slow-moving customer-managed deployments remain reachable for unauthenticated code execution.

Defused says attackers are now exploiting CVE-2026-6875 in the wild. That turns the patch into a dividing line: the hosted estate is covered, but self-hosted and partner-managed instances stay at risk until the fix lands there.

For operators, the real question is no longer whether ServiceNow shipped a fix. It is whether the instance they control is still running the vulnerable code.

6 sources · Jul 21

CVE-2026-6875

NVD KEV

EPSS 78% (100th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-07-20

Every edition of this story: Lagging ServiceNow Instances Stay Exposed After Patch Rollout

More from today