Overview
A critical vulnerability in the ServiceNow AI Platform, identified as CVE-2026-6875, is being actively exploited by attackers. This pre-authentication code injection flaw allows unauthenticated users to escape the platform's script sandbox and execute arbitrary code on targeted instances. Researchers from Searchlight Cyber discovered this vulnerability and reported it to ServiceNow in early April 2026. The exploitation of this vulnerability poses significant risks to organizations using the ServiceNow AI Platform, as it could lead to unauthorized access and control over sensitive workflows and data. Companies are urged to take immediate action to safeguard their systems against potential attacks.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: ServiceNow AI Platform
- Action Required: Organizations should apply any available patches from ServiceNow and review their security configurations to limit unauthorized access.
- Timeline: Disclosed on April 2026
Original Article Summary
Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance. The vulnerability was unearthed by Searchlight Cyber researchers and reported to ServiceNow in early April 2026. The … More → The post ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) appeared first on Help Net Security.
Impact
ServiceNow AI Platform
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Disclosed on April 2026
Remediation
Organizations should apply any available patches from ServiceNow and review their security configurations to limit unauthorized access. Additionally, implementing monitoring for unusual activity on ServiceNow instances may help detect potential exploitation attempts.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, RCE, and 1 more.