Security · 7h ago
ServiceNow AI Platform Flaw Under Active Attack, Allows Remote Code Execution
A critical sandbox escape vulnerability (CVE-2026-6875, CVSS 9.5) in ServiceNow's AI Platform is being actively exploited in the wild, according to Defused Cyber. The flaw allows unauthenticated attackers to execute arbitrary code. Patches were released but many systems remain unpatched, leaving them exposed.
Meridian48 take
This is a high-severity, actively exploited vulnerability in a widely used enterprise platform, underscoring the urgency of patching even as AI features expand attack surfaces.
Read the full reporting
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution →
The Hacker News
servicenowvulnerability