CVE-2026-6875 ServiceNow AI Platform bug enables unauthenticated code execution
Source headline: Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Intelligence Summary
Defused Cyber says threat actors are actively exploiting a critical ServiceNow AI Platform vulnerability. The issue is tracked as CVE-2026-6875 and has a CVSS score of 9.5. It is described as a sandbox escape flaw that can allow an unauthenticated attacker to execute arbitrary code. Organizations using the affected ServiceNow AI Platform should treat this as an active exploitation risk. Verify patch status, restrict access where possible, and review for signs of anomalous AI platform activity.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.