[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOzbvgcPzSXk7aEqnRZDRvqLAOOly4oP93dFAHuVUd0U":3},{"article":4,"iocs":53},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"b6a7bc61-f9ad-45dd-9de7-85405e54bddb","Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution","critical-servicenow-ai-platform-flaw-exploited-for-unauthenticated-code-executio-c8dac0","Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. Patches for the flaw were","Threat actors are actively exploiting CVE-2026-6875, a critical sandbox escape vulnerability in the ServiceNow AI Platform that allows unauthenticated users to execute arbitrary code. Patches were released by ServiceNow throughout June, and the company is enhancing instance security by restricting code execution in sandbox contexts. Exploitation targets the pre-authentication endpoint '\u002Fassessment_thanks.do' using HTTP POST requests.","Critical ServiceNow AI Platform flaw CVE-2026-6875 is being exploited for unauthenticated code execution.","Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution Ravie LakshmananJul 21, 2026Vulnerability \u002F Artificial Intelligence Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. Patches for the flaw were released by ServiceNow throughout June in the following versions - Brazil EA and Brazil GA Australia Patch 2 Zurich Patch 7b and Zurich Patch 9 Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13 Searchlight Cyber, which disclosed additional technical specifics, said it reported the issue on April 1, 2026, adding it allows a complete compromise of the ServiceNow instance as well as all connected proxy servers. Besides rolling out a fix, ServiceNow is \"enhancing instance security by severely restricting the type of code that can run in sandbox contexts,\" security researcher Adam Kues noted. According to Defused, the exploitation efforts target the same pre-authentication endpoint (\"\u002Fassessment_thanks.do\") using HTTP POST requests, although the sandbox-escape gadget leads to the same code execution primitive by a different route documented in the proof-of-concept (PoC) exploit. In light of active exploitation, customers of self-hosted versions are advised to apply the fixes, if not already, to counter the threat. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Application Security, artificial intelligence, Cloud security, enterprise security, Vulnerability ⚡ Top Stories This Week URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code ⭐ Featured Resources What Security Teams Must Defend in the New AI Software Supply Chain Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See","https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fcritical-servicenow-ai-platform-flaw.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjAYYV6u5s-uKU-FXeqsoZ9Bk7nvzW1gPYVuoykmnuzLBQCK0jvX7rAO12mK5FVX06ovTJHZLUUXDkFmYk88oyKdFSYByRPSL5MUuAqikrTIVEpVzOcR9j4Rn0Fmje7-VwBAO09Yl8Y4cTUVNFwTXf2FV2c9C8oyNi5coAMCMLn5WF5Fbqtyt-tDZ3MVsO0\u002Fs1600\u002Fservicenow.jpg","2026-07-21T06:29:26+00:00","2026-07-21T08:00:16.744681+00:00",9,[18,21,24,27],{"name":19,"type":20},"ServiceNow AI Platform","product",{"name":22,"type":23},"ServiceNow","vendor",{"name":25,"type":26},"Defused Cyber","threat_actor",{"name":28,"type":29},"Artificial Intelligence","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":30,"icon":32,"name":33,"slug":34},null,"Vulnerabilities","vulnerabilities",[36,38,43,48],{"category":37},{"id":30,"icon":32,"name":33,"slug":34},{"category":39},{"id":40,"icon":32,"name":41,"slug":42},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":44},{"id":45,"icon":32,"name":46,"slug":47},"c70f3a41-2f0c-4608-870d-b8cbcd8be076","Cloud Security","cloud-security",{"category":49},{"id":50,"icon":32,"name":51,"slug":52},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[54],{"type":55,"value":56,"context":57},"cve","CVE-2026-6875","Critical sandbox escape vulnerability in ServiceNow AI Platform."]