Wire · regulatory
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 21 July 2026 · Fusion42 review
A critical unauthenticated code execution vulnerability (CVE-2026-6875, CVSS 9.5) in ServiceNow's AI Platform is being actively exploited in the wild. The flaw allows attackers to escape the sandbox and compromise entire ServiceNow instances and connected proxy servers; patches were released in June across multiple versions.
This Wire brief sits within Fusion42's coverage of Enterprise Software, Cybersecurity and Security Infrastructure, and 3 sources have reported it between 20 Jul 2026 and 21 Jul 2026.
◆ ◆ The Wire takeaway
If you're building on ServiceNow or selling to ServiceNow shops, your customers' instances are under active attack right now. Patch deployment is a hard deadline this week, and unpatched instances are completely compromised.
◆ Coverage
3 sources · first reported 20 Jul 2026 · latest 21 Jul 2026
◆ Related on Wire
◆ Topics