importantSYS.SOURCE: The Hacker News• 2026-07-21T11:59:26+05:30
Critical ServiceNow AI Platform Vulnerability CVE-2026-6875 Exploited for Unauthenticated Code Execution
A critical sandbox escape vulnerability (CVE-2026-6875, CVSS 9.5) in the ServiceNow AI Platform is being actively exploited for unauthenticated code execution. Patches were released in June, and customers are urged to apply fixes to prevent full system compromise.
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber.
In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code.
Patches for the flaw were
*** END OF TRANSMISSION ***