Post
CRITICAL

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

· rce · cve · vulnerability

Threat intelligence firm Defused Cyber is observing in-the-wild exploitation of CVE-2026-6875 (CVSS 9.5), a sandbox escape vulnerability in the ServiceNow AI Platform that lets an unauthenticated attacker run arbitrary code. Patches for the flaw have already been released; organizations running the ServiceNow AI Platform should confirm they’ve applied them.