By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Critical ServiceNow AI Platform Flaw Exploited

Threat actors are actively exploiting a critical security flaw within the ServiceNow AI Platform, as reported by Defused Cyber. The firm detailed on X that exploitation in the wild has been observed for CVE-2026-6875, a vulnerability with a CVSS score of 9.5. This flaw represents a sandbox escape that could permit an unauthenticated user to execute arbitrary code on affected systems.
The vulnerability specifically targets the AI Platform, a component of ServiceNow's broader suite of enterprise IT service management solutions. The potential for unauthenticated code execution poses a significant risk, as it bypasses standard security controls and could allow attackers to gain unauthorized access and control over sensitive data and system functions. The severity, indicated by the 9.5 CVSS score, places it in the "critical" category, demanding immediate attention from organizations using the platform.
ServiceNow has released patches to address CVE-2026-6875. Organizations utilizing the ServiceNow AI Platform are strongly advised to apply these updates as soon as possible to mitigate the risk of exploitation. The ongoing in-the-wild exploitation underscores the urgency of patching, as threat actors are actively seeking to leverage this vulnerability. Further details on the specific methods of exploitation and the full impact are expected to emerge as security researchers continue to analyze the threat.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.