CRITICAL
ServiceNow AI Platform Flaw Actively Exploited for Unauthenticated RCE
ServiceNow’s AI Platform contains a critical sandbox escape vulnerability, CVE-2026-6875 (CVSS 9.5), that allows an unauthenticated attacker to run arbitrary code. Threat intelligence firm Defused Cyber reported observing in-the-wild exploitation just days after the flaw was disclosed and patched. Organizations running ServiceNow AI Platform should confirm patches are applied and review logs for exploitation indicators.