CVE Tools
Back to feed
Exploited in the wild ServiceNow AI Platform rce ServiceNow web-app

Critical ServiceNow code execution flaw now exploited in attacks

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

A critical vulnerability in ServiceNow's AI Platform, CVE-2026-6875, is now being actively exploited by attackers, according to threat intelligence firm Defused. The flaw allows unauthenticated users to break out of a sandbox and execute arbitrary code remotely. Despite patches being issued on July 13, real-world attacks were detected just days later. ServiceNow urges all users to apply the latest security updates immediately.