Critical

Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875

Security Affairs
Actively Exploited
2 Sources
Reporting on this topic
Help Net SecuritySecurity Affairs

Overview

A serious vulnerability in ServiceNow's AI Platform, identified as CVE-2026-6875, is being actively exploited by attackers. This flaw allows for unauthenticated remote code execution on self-hosted instances of the platform. Researchers from Searchlight Cyber disclosed the vulnerability on July 14, 2023, and ServiceNow promptly released patches for affected systems on the same day. However, reports indicate that attacks exploiting this flaw began shortly after, on July 17. Organizations using self-hosted ServiceNow instances need to apply the patches immediately to protect against potential breaches, as the vulnerability poses a significant risk to their data and operations.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: ServiceNow AI Platform (self-hosted instances)
  • Action Required: ServiceNow released patches for self-hosted instances on July 14, 2023.
  • Timeline: Disclosed on July 14, 2023

Original Article Summary

Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical pre-authentication remote code execution vulnerability, tracked as CVE-2026-6875, in the ServiceNow AI Platform on July 14. The same day, ServiceNow released patches for self-hosted instances. Since July 17, attackers have started exploiting it in […]

Impact

ServiceNow AI Platform (self-hosted instances)

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Disclosed on July 14, 2023

Remediation

ServiceNow released patches for self-hosted instances on July 14, 2023. Users should apply these patches as soon as possible to mitigate the risk of exploitation.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Exploit, Vulnerability, and 2 more.

Multiple Sources: This threat is being reported by 2 different security sources, indicating significant concern within the cybersecurity community.