← Back to blog

Critical ServiceNow AI Flaw Enables Unauthenticated Code Execution

A critical sandbox escape vulnerability in ServiceNow's AI Platform is being actively exploited by threat actors. Organizations using the platform should take immediate action to patch and monitor for signs of compromise.

TL;DR

  • CVE-2026-6875 is a critical sandbox escape flaw in ServiceNow AI Platform with CVSS score 9.5
  • Exploitation allows unauthenticated attackers to execute arbitrary code
  • Threat intelligence firm Defused Cyber reports active in-the-wild exploitation
  • Patches are available but require immediate deployment to prevent compromise
  • Organizations should audit ServiceNow instances and implement enhanced monitoring

Security teams are facing a rapidly evolving threat as attackers exploit a critical vulnerability in ServiceNow's AI Platform. The flaw, identified as CVE-2026-6875, represents a severe sandbox escape issue that enables unauthenticated users to execute arbitrary code on affected systems.

According to threat intelligence researchers at Defused Cyber, the vulnerability is already being exploited in real-world attacks. With a CVSS score of 9.5, this represents a critical risk that demands immediate attention from organizations relying on ServiceNow's enterprise solutions.

The vulnerability underscores the growing attack surface associated with AI-powered business platforms and highlights the importance of rapid patch deployment and proactive threat hunting.

Vulnerability Details

  • CVE-2026-6875 is a sandbox escape vulnerability affecting ServiceNow AI Platform
  • The flaw has a critical CVSS score of 9.5, indicating severe impact potential
  • Attackers can achieve unauthenticated remote code execution without valid credentials
  • The vulnerability bypasses standard security controls through sandbox escape techniques

Active Exploitation and Response

  • Defused Cyber reports confirmed in-the-wild exploitation of the vulnerability
  • Threat actors are targeting organizations without patched ServiceNow instances
  • Patches have been released by ServiceNow but require immediate deployment
  • Organizations should implement enhanced monitoring for suspicious ServiceNow activity
  • Security teams should audit access logs and consider network segmentation for ServiceNow environments

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Critical ServiceNow AI Flaw Enables Unauthenticated Code Execution — Agent Breach Blog | Agent Breach