Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Summary

A critical vulnerability (CVE-2026-6875) in ServiceNow's AI Platform is being actively exploited by threat actors. This flaw allows unauthenticated users to execute arbitrary code, posing a significant risk to organizations using the platform.

IFF Assessment

FOE

The exploitation of a critical vulnerability allowing unauthenticated code execution is bad news for defenders as it presents an immediate and severe risk.

Severity

9.5 Critical

The CVSS score of 9.5 indicates a critical severity, primarily due to the potential for unauthenticated remote code execution (Attack Vector: Network, Privileges Required: None, User Interaction: None, Impact: High).

Defender Context

Defenders must prioritize patching this vulnerability in ServiceNow AI Platform instances immediately, as it is already being actively exploited. Organizations should also enhance their monitoring for signs of compromise related to unauthenticated code execution and unauthorized system access.

Read Full Story →