A critical remote code execution vulnerability, tracked as CVE-2026-6875, has been patched in the ServiceNow AI platform but is reportedly being exploited in the wild. It is described as a sandbox escape issue that allows unauthenticated attackers to execute arbitrary code. ServiceNow provided patches for hosted instances, while self-hosted customers must apply them manually.
The cybersecurity firm Searchlight Cyber released details on how the vulnerability could be exploited, which was subsequently observed being exploited by Defused. While ServiceNow initially reported no evidence of active exploitation, they have advised all customers to apply the patches as soon as possible.