Lagging ServiceNow Instances Stay Exposed After Patch Rollout
The risk shifted from a vendor fix notice to live exposure on any ServiceNow AI Platform instance that has not yet taken the update. Hosted tenants were already updated, but unpatched or slow-moving customer-managed deployments remain reachable for unauthenticated code execution.
Defused says attackers are now exploiting CVE-2026-6875 in the wild. That turns the patch into a dividing line: the hosted estate is covered, but self-hosted and partner-managed instances stay at risk until the fix lands there.
For operators, the real question is no longer whether ServiceNow shipped a fix. It is whether the instance they control is still running the vulnerable code.