ServiceNow AI Platform RCE exploited in wild: CVE-2026-6875
Threat-intel firm Defused reports active exploitation of ServiceNow AI Platform CVE-2026-6875, a week after ServiceNow said it saw none.
Exploitation reported. Threat-intelligence firm Defused told BleepingComputer on 2026-07-20 that attackers have begun exploiting CVE-2026-6875, a critical unauthenticated remote code execution vulnerability in the ServiceNow AI Platform. Confidence: as-reported by Defused via BleepingComputer. Independent second-source in-wild exploitation, at time of writing: none.
ServiceNow’s own KB3137947 advisory, published a week earlier and mirrored in the NVD entry on 2026-07-13, described the flaw and stated the vendor was “not currently aware of exploitation against ServiceNow instances.” That posture stood for seven days. It no longer does.
Timeline
- 2026-07-13 — ServiceNow publishes KB3137947; NVD ingests CVE-2026-6875 the same day. Vendor states no known exploitation. Confidence: primary source.
- ~2026-07-13 onward — ServiceNow deploys the security update to hosted instances; patches shipped to self-hosted customers and partners for on-prem application. Confidence: as-stated by vendor.
- 2026-07-20 — Defused reports observed exploitation attempts targeting ServiceNow AI Platform instances. Confidence: as-reported by Defused, single-source at time of writing.
- CISA KEV status: not listed at time of writing. Watch the KEV catalog and our KEV tracker — if this lands there, the federal 21-day patch deadline clock starts.
What the advisory actually says
Per NVD’s description, the flaw allows “an unauthenticated user, in certain circumstances, [to] execute code within the ServiceNow platform.” The public description does not spell out the trigger conditions or the affected surface within the AI Platform. Confidence: as-published by ServiceNow via NVD. We are not filling in the mechanics from speculation, and we are not reproducing exploitation detail even if a PoC surfaces publicly.
CVSS 4.0 base score is 9.5, critical. The vector (AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) reads: network reachable, no privileges, no user interaction, full impact on vulnerable and subsequent system confidentiality, integrity, and availability — but with attack complexity marked High. That last bit is the reason ServiceNow’s initial “no exploitation observed” line held for a week: the flaw is not turn-key. Defused’s reporting suggests that condition is now being met in the wild by at least one actor. Attribution: none stated.
What is unconfirmed
- Which specific AI Platform builds and configurations are reachable. ServiceNow’s KB is customer-gated and NVD’s public description is short. Self-hosted operators should read KB3137947 directly.
- Volume and targeting. Defused reports exploitation; no victim count, no vertical, no geography published at time of writing. Unstated.
- Attribution. No named actor. Unattributed.
- Whether hosted (Now/SaaS) instances are still exposed after ServiceNow’s push. Vendor states hosted was updated. Self-hosted is where the current exposure sits. If your instance is hosted and you have not been told otherwise, treat as patched; if self-hosted, treat as at-risk until KB3137947 is applied.
What to do
- Self-hosted or partner-hosted ServiceNow AI Platform: apply KB3137947 now. If you cannot patch this week, that is a choice, and one worth flagging to your risk owner today given the shift from “vendor says no known exploitation” to “single-source reports of active exploitation” inside a seven-day window.
- Hosted (Now/SaaS): confirm your instance received the security update. ServiceNow states hosted was patched; verify against the KB.
- Detection: the KB and NVD entry do not publish indicators. If your MDR or EDR vendor has ServiceNow-AI-Platform-specific detection notes, ask for them now, not after a triage call. This vulnerability class is exactly where “we thought hosted took care of it” gaps tend to live.
- KEV watch: if this lands on CISA’s KEV catalog in the next few days, the federal patch deadline is real for FCEB agencies and a strong signal for everyone else. We will update if that happens.
Context
Two recent items on this desk to place this against:
- WordPress Core wp2shell (CVE-2026-60137) — same pattern this week: patch out, PoC out, in-wild exploitation reported within days.
- Hugging Face autonomous-agent breach — a reminder that “AI Platform” surfaces are not exempt from the same code-execution primitives that have haunted every other enterprise SaaS surface. This one is a ServiceNow bug, not an AI-agent bug — but the label on the product is the same word, and it will be read that way in enterprise headlines this week.
Sources
- BleepingComputer, 2026-07-20: Critical ServiceNow code execution flaw now exploited in attacks — the Defused disclosure.
- NVD: CVE-2026-6875 — published 2026-07-13, CVSS 4.0 base 9.5.
- ServiceNow KB3137947: Vendor advisory (customer-gated).
- CISA: Known Exploited Vulnerabilities Catalog.
Confidence, consolidated: CVE and patch — confirmed by vendor and NVD; in-wild exploitation — as-reported by Defused, single-source at time of writing; victim count, targeting, attribution — unstated; KEV listing — not present as of 2026-07-20.
- [ CRITICAL ] CVE-2026-6875 ServiceNow AI Platform unauthenticated remote code execution
Found this useful? Share it.