← Back

Wire · founder news, decoded · regulatory

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Published

21 July 2026

Topic

regulatory

Sectors

Enterprise SoftwareCybersecurity

Source

Read at thehackernews.com

Verified

Fusion42 · 21 July 2026 · Fusion42 review

A critical unauthenticated code execution vulnerability (CVE-2026-6875, CVSS 9.5) in ServiceNow's AI Platform is being actively exploited in the wild. The flaw allows attackers to escape the sandbox and compromise entire ServiceNow instances and connected proxy servers; patches were released in June across multiple versions.

This Wire brief sits within Fusion42's coverage of Enterprise Software and Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

The Wire takeaway

If you're building on ServiceNow or selling to ServiceNow shops, your customers' instances are under active attack right now. Patch deployment is a hard deadline this week, and unpatched instances are completely compromised.

Related on Wire

Topics

Enterprise Software · Cybersecurity · servicenow · zero-day · rce · active-exploitation · patch-urgency