ServiceNow AI Platform Vulnerability CVE-2026-6875 Exploited in the Wild
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875, which allows for remote code execution, is confirmed to be exploited in the wild. Self-hosted ServiceNow customers are particularly at risk if they have not yet applied the available patches.
What happened
According to multiple independent sources, the vulnerability CVE-2026-6875 in the ServiceNow AI platform is being actively exploited. This high-severity flaw enables unauthenticated remote code execution via a sandbox escape. ServiceNow released patches for this vulnerability in June, but self-hosted customers must manually apply these updates.
The exploitation targets a pre-authentication endpoint using HTTP POST requests. Cybersecurity firm Defused Cyber initially reported observing in-the-wild exploitation shortly after the vulnerability disclosure. ServiceNow has also enhanced instance security by restricting the type of code that can run in sandbox contexts.
To assess your exposure, check if you are using a self-hosted version of ServiceNow and verify that the latest patches have been applied. Monitor your environments for any signs of exploitation. For more detailed technical information and patch versions, consult the primary sources listed.
How 0Day mitigates this
servicenow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.