logo

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

ID: db22e1b5-b27b-5003-876e-dd3a9f84704d

STIX ID: report--db22e1b5-b27b-5003-876e-dd3a9f84704d

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: [email protected] (The Hacker News)

...
...

Threat intelligence firms reported active exploitation of CVE-2026-6875, a critical (CVSS 9.5) sandbox escape in the ServiceNow AI Platform that can enable unauthenticated arbitrary code execution and full instance compromise; ServiceNow released patches and is limiting sandbox code execution while noting it has not observed exploitation against ServiceNow-hosted instances, and self-hosted customers are urged to apply fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.