Threat intelligence firm Defused confirmed that the critical vulnerability CVE-2026-6875 in the ServiceNow AI Platform is being actively exploited. The vulnerability enables attackers to escape the platform's sandbox environment and execute remote code without authentication. The flaw was discovered by Searchlight Cyber in April, and ServiceNow released patches for its own hosted systems on July 13.
Defused noted that payloads exploiting this vulnerability target the same endpoint as previously proven methods but use a different technique to achieve sandbox escape. ServiceNow's official statement still claims it is unaware of active exploitation, but urges all customers to update their systems as soon as possible.
The ServiceNow AI Platform is used by 85% of Fortune 500 companies and processes 100 billion workflows annually. Security teams detect only 54% of successful attacks and alert on just 14%; the remainder go unnoticed.
