CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Critical ServiceNow code execution flaw now exploited in attacks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2815

As cited

Copy frozen at (site build).

vulnerabilities

Critical ServiceNow code execution flaw now exploited in attacks

A critical code execution vulnerability identified as CVE-2026-6875 in the ServiceNow AI Platform is now being actively exploited in attacks, according to threat intelligence research. Organizations running affected ServiceNow instances face immediate risk from threat actors leveraging this flaw.

Why it matters: ServiceNow administrators and security teams need to prioritize patching immediately, as active exploitation confirms this vulnerability is a high-priority target for attackers seeking remote code execution.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Critical ServiceNow code execution flaw now exploited in attacks

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Critical ServiceNow code execution flaw now exploited in attacks

Attackers have begun exploiting CVE-2026-6875, a critical vulnerability in the ServiceNow artificial intelligence (AI) Platform, according to threat intelligence company Defused. Active exploitation of the flaw demonstrates that adversaries have transitioned from theoretical proof-of-concept to real-world attacks. Organizations running the affected ServiceNow AI Platform are at immediate risk.

Why it matters: ServiceNow customers using the AI Platform face active exploitation of this critical vulnerability and should prioritize patching immediately to prevent unauthorized code execution and data access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Critical ServiceNow code execution flaw now exploited in attacks

Attackers have begun exploiting CVE-2026-6875, a critical vulnerability in the ServiceNow artificial intelligence (AI) Platform, according to threat intelligence company Defused. Active exploitation of the flaw demonstrates that adversaries have transitioned from theoretical proof-of-concept to real-world attacks. Organizations running the affected ServiceNow AI Platform are at immediate risk.

Why it matters: ServiceNow customers using the AI Platform face active exploitation of this critical vulnerability and should prioritize patching immediately to prevent unauthorized code execution and data access.

VendorsServiceNow
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary