← Back

Wire · regulatory

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Published

21 July 2026

Topic

regulatory

Sectors

Enterprise SoftwareCybersecuritySecurity Infrastructure

Source

Read at thehackernews.com

Verified

Fusion42 · 21 July 2026 · Fusion42 review

A critical unauthenticated code execution vulnerability (CVE-2026-6875, CVSS 9.5) in ServiceNow's AI Platform is being actively exploited in the wild. The flaw allows attackers to escape the sandbox and compromise entire ServiceNow instances and connected proxy servers; patches were released in June across multiple versions.

This Wire brief sits within Fusion42's coverage of Enterprise Software, Cybersecurity and Security Infrastructure, and 3 sources have reported it between 20 Jul 2026 and 21 Jul 2026.

◆ The Wire takeaway

If you're building on ServiceNow or selling to ServiceNow shops, your customers' instances are under active attack right now. Patch deployment is a hard deadline this week, and unpatched instances are completely compromised.

Coverage

3 sources · first reported 20 Jul 2026 · latest 21 Jul 2026

Related on Wire

Topics

Enterprise SoftwareCybersecuritySecurity Infrastructureservicenowzero-dayrceactive-exploitationpatch-urgency