Wire · founder news, decoded · regulatory
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
◆ Published
21 July 2026
◆ Topic
regulatory
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 21 July 2026 · Fusion42 review
A critical unauthenticated code execution vulnerability (CVE-2026-6875, CVSS 9.5) in ServiceNow's AI Platform is being actively exploited in the wild. The flaw allows attackers to escape the sandbox and compromise entire ServiceNow instances and connected proxy servers; patches were released in June across multiple versions.
This Wire brief sits within Fusion42's coverage of Enterprise Software and Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
If you're building on ServiceNow or selling to ServiceNow shops, your customers' instances are under active attack right now. Patch deployment is a hard deadline this week, and unpatched instances are completely compromised.
◆ Related on Wire
- Critical ServiceNow code execution flaw now exploited in attacks20 July 2026
- Attackers Exploit ServiceNow CVE-2026-6875 via Multiple Sandbox-Escape Routes20 July 2026
- Critical ServiceNow AI flaw exploited days after patch release | news | SC Media20 July 2026
- Critical Oracle EBS bug added to CISA list of exploited vulnerabilities | news | SC Media17 July 2026
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV17 July 2026
- CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities17 July 2026
◆ Topics
Enterprise Software · Cybersecurity · servicenow · zero-day · rce · active-exploitation · patch-urgency