CVE-2026-6875
EPSS 78% (100th percentile).
Vulnerabilities · 55 days ago
The risk shifted from a vendor fix notice to live exposure on any ServiceNow AI Platform instance that has not yet taken the update. Hosted tenants were already updated, but unpatched or slow-moving customer-managed deployments remain reachable for unauthenticated code execution.
Defused says attackers are now exploiting CVE-2026-6875 in the wild. That turns the patch into a dividing line: the hosted estate is covered, but self-hosted and partner-managed instances stay at risk until the fix lands there.
For operators, the real question is no longer whether ServiceNow shipped a fix. It is whether the instance they control is still running the vulnerable code.
EPSS 78% (100th percentile).
6 sources covering this story
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution.
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Attackers exploit CVE-2026-6875 in ServiceNow AI Platform, a pre-auth sandbox escape that could compromise instances and connected proxy servers.
ServiceNow’s sandbox escape RCE hole now exploited in the wild
But the concern goes beyond the now-patched hole’s exploitation and focuses on the lack of security surrounding any sandbox in the AI era.
ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) - Help Net Security
Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform.
Critical ServiceNow code execution flaw now exploited in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow
A critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code.
Risolta vulnerabilità in ServiceNow
Risolta una vulnerabilità “critica” in ServiceNow AI Platform, piattaforma AI che unifica dati, workflow, automazione e AI agent in un unico ambiente cloud aziendale.
Part of the PlainSec briefing for 2026-07-22