A critical code execution vulnerability, identified as CVE-2026-6875, in the ServiceNow AI Platform is being actively exploited by attackers, as reported by threat intelligence company Defused1. This flaw allows malicious actors to execute arbitrary code, posing a significant threat to organizations relying on the platform. The vulnerability is currently under discussion, with Intel involved, to determine the extent of exploitation and the necessary response. ServiceNow users are advised to take immediate action, as the exploitation status of CVE-2026-6875 will dictate whether a patch should be applied promptly or if monitoring is sufficient. The active exploitation of this vulnerability underscores the importance of timely patching and highlights the need for organizations to prioritize vulnerability management. So what matters to practitioners is that they must assess their ServiceNow infrastructure's exposure to CVE-2026-6875 and take corrective action to prevent potential attacks.
Critical ServiceNow code execution flaw now exploited in attacks
⚠️ Critical Alert
Why This Matters
CVE-2026-6875 is in active discussion involving Intel — exploitation status determines whether this is patch-now or monitor.
References
- BleepingComputer. (2026, July 20). Critical ServiceNow code execution flaw now exploited in attacks. BleepingComputer. https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/
Original Source
BleepingComputer
Read original →