Skip to content
feed: live
>_ 0dayNews
CVE Record
[ CRITICAL ] CVE-2026-6875

ServiceNow AI Platform unauthenticated remote code execution

An unauthenticated attacker can, under certain circumstances, execute code on the ServiceNow AI Platform. Patched by ServiceNow on hosted instances; self-hosted customers and partners must apply the shipped updates.

cat cve-2026-6875.json
Vendor
ServiceNow
Product
ServiceNow AI Platform
CVSS
9.5
EPSS (exploit probability)
N/A
Status
exploited-in-wild
Published

NVD tracks CVE-2026-6875 as a remote code execution flaw in the ServiceNow AI Platform, exploitable by an unauthenticated user under conditions ServiceNow does not spell out in the public description. CVSS 4.0 base score 9.5, critical (vector AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H).

ServiceNow addressed the vulnerability by pushing a security update to hosted instances and shipping patches and family releases to self-hosted customers and partners. At disclosure, the vendor’s own advisory stated they were “not currently aware of exploitation against ServiceNow instances.” That posture changed on 2026-07-20 when threat-intelligence firm Defused, via BleepingComputer, reported active exploitation in the wild.

Status flipped here from patched to exploited-in-wild to reflect the Defused report. No CISA KEV entry as of the publish date of the covering article.