Exploited in the wild ServiceNow AI Platform rce ServiceNow web-app
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
CVE Tools coverage
A critical vulnerability in ServiceNow AI Platform, identified as CVE-2026-6875, is currently being actively exploited by attackers to execute arbitrary code without authentication. The flaw, rated with a CVSS score of 9.5, enables sandbox escape and has been observed in real-world attacks targeting the "/assessment_thanks.do" endpoint. Patches have been issued for several versions including Brazil EA/GA, Australia Patch 2, Zurich Patch 7b/9, and Yokohama Patch 12 Hot Fix 1b/Patch 13. Security researchers emphasize the need for immediate patching to prevent full system compromise.