Critical ServiceNow code execution flaw now exploited in attacks
CVE-2026-6875 in the ServiceNow AI Platform is now under active exploitation, giving attackers code execution on one of Europe's most prevalent ITSM platforms — emergency patching should be treated as a top priority this week.
Summary written by editorial AI · Source link below
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]
Editorial Analysis
Active exploitation of a critical RCE vulnerability in ServiceNow directly threatens any enterprise using the platform for IT service management, with potential for lateral movement into connected systems.
Immediately patch all ServiceNow instances against CVE-2026-6875, activate WAF mitigations, and initiate threat hunting for indicators of prior exploitation.
A critical vulnerability in ServiceNow's AI Platform is being actively exploited — enterprises should treat patching as an emergency given the platform's ubiquity in European IT operations.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at BleepingComputer in a new tab.
More from the Vulnerabilities Desk
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores2d
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code2d
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities3d
- Government Rails Site Hit Hours After CVE Patch3d
- Critical Citrix NetScaler auth bypass now leveraged in attacks3d