Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
A critical remote code execution vulnerability in ServiceNow's AI platform, tracked as CVE-2026-6875, is being actively exploited just days after its disclosure. The flaw allows unauthenticated attackers to bypass sandbox protections and execute arbitrary code under specific conditions. While ServiceNow has deployed patches for hosted instances, self-hosted customers are responsible for applying them. Cybersecurity firm Searchlight Cyber published technical details on July 14, followed by reports from Defused indicating real-world exploitation using those methods. Although ServiceNow initially stated it had no evidence of active attacks, a spokesperson confirmed awareness of the exploitation but noted it appears limited to non-hosted environments.