Remote Code Execution Vulnerability in ServiceNow AI Platform
CVE-2026-6875
Key Information:
- Vendor
Servicenow
- Status
- Vendor
- CVE Published:
- 13 July 2026
Badges
What is CVE-2026-6875?
CVE-2026-6875 is a significant remote code execution vulnerability identified in the ServiceNow AI platform, a widely used service management solution designed to streamline various business processes, including IT service management and customer support. This vulnerability allows an unauthorized user, under specific conditions, to execute arbitrary code within the platform. The implications of such an exploit can be dire; it may enable attackers to manipulate system functionality, access sensitive data, and disrupt essential services. The vulnerability has been addressed through security updates that ServiceNow deployed to both hosted and self-hosted customers, emphasizing the importance of immediate remediation to safeguard organizational infrastructure.
Potential impact of CVE-2026-6875
-
Unauthorized Code Execution: The core risk associated with CVE-2026-6875 is the ability for unauthenticated users to run malicious code. This can lead to significant system compromises, allowing attackers full control over the platform, which can severely disrupt business operations.
-
Data Breach Risk: Exploitation of this vulnerability can potentially expose sensitive organizational data. If attackers gain control over the ServiceNow platform, they can access, alter, or exfiltrate confidential information, leading to data breaches that can impact privacy and compliance.
-
Operational Disruption: Given that ServiceNow is integral to many organizational processes, successful exploitation may result in significant operational downtime. This could hinder productivity, affect customer interactions, and lead to a loss of revenue, thereby damaging an organization's reputation and trustworthiness.
Affected Version(s)
ServiceNow AI Platform 0
ServiceNow AI Platform 0
ServiceNow AI Platform 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached - Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: AI agents are still logging in as humans Most large
1 week ago
Hackers are Actively Exploiting ServiceNow Vulnerability in the Wild
A critical ServiceNow RCE vulnerability is being actively exploited to escape the script sandbox and execute code.
2 weeks ago

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Attackers exploit CVE-2026-6875 in ServiceNow AI Platform, a pre-auth sandbox escape that could compromise instances and connected proxy servers.
2 weeks ago
References
EPSS Score
24% chance of being exploited in the next 30 days.
CVSS V4
Timeline
- 💰
Used in Ransomware
- 🟡
Public PoC available
- 📈
Vulnerability started trending
- 👾
Exploit known to exist
- 📰
First article discovered by It Security News
Vulnerability published
Vulnerability Reserved
