Post
CRITICAL

ServiceNow AI Platform Flaw Actively Exploited for Unauthenticated RCE

· rce · cve · vulnerability

ServiceNow’s AI Platform contains a critical sandbox escape vulnerability, CVE-2026-6875 (CVSS 9.5), that allows an unauthenticated attacker to run arbitrary code. Threat intelligence firm Defused Cyber reported observing in-the-wild exploitation just days after the flaw was disclosed and patched. Organizations running ServiceNow AI Platform should confirm patches are applied and review logs for exploitation indicators.