ServiceNow AI Platform critical vulnerability now under active exploitation

A critical code execution flaw in ServiceNow's enterprise AI platform is being actively exploited, threatening organizations using the widely deployed IT service management system.

Abstract network visualization showing security vulnerability in enterprise platform
AI-generated illustration · Sylvaris

Active Exploitation Confirmed

Threat intelligence firm Defused reports that attackers have begun exploiting CVE-2026-6875, a critical vulnerability in the ServiceNow AI Platform. The flaw allows remote code execution, giving attackers the ability to run arbitrary commands on affected systems.

ServiceNow provides IT service management and workflow automation to thousands of enterprise customers globally. The AI Platform component extends these capabilities with machine learning features for automation and decision support.

Scope and Exposure

The vulnerability affects organizations running the ServiceNow AI Platform, which is integrated into many enterprise IT operations. Organizations typically use ServiceNow to manage help desk tickets, automate IT processes, and coordinate internal workflows.

The active exploitation designation means attackers have working exploit code and are targeting vulnerable installations. This elevates the urgency for organizations to apply available patches or implement mitigations.

Response Actions

Organizations using ServiceNow should immediately verify their patch status and review access logs for signs of compromise. ServiceNow typically issues security advisories through its customer portal with specific remediation steps for identified vulnerabilities.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.