A critical vulnerability in ServiceNow's AI Platform, tracked as CVE-2026-6875, is being exploited by attackers to execute remote code on self-hosted instances without authentication. The flaw was disclosed by Searchlight Cyber researchers on July 14, prompting ServiceNow to release patches for self-hosted instances the same day. However, attackers began exploiting the vulnerability in the wild just three days later, on July 17. The pre-authentication remote code execution vulnerability expands the active attack surface, making it essential for organizations to prioritize mitigation based on their exposure and evidence of exploitation1. This vulnerability poses a significant risk to self-hosted ServiceNow instances, and practitioners should take immediate action to patch and monitor their systems. The rapid exploitation of this flaw highlights the importance of prompt patching and vigilance in protecting against emerging threats.