Remote Code Execution Vulnerability in ServiceNow AI Platform
CVE-2026-6875

9.5CRITICAL

Key Information:

Vendor

Servicenow

Vendor
CVE Published:
13 July 2026

Badges

📈 Trended📈 Score: 5,260💰 Ransomware👾 Exploit Exists🟡 Public PoC🟣 EPSS 24%📰 News Worthy

What is CVE-2026-6875?

CVE-2026-6875 is a significant remote code execution vulnerability identified in the ServiceNow AI platform, a widely used service management solution designed to streamline various business processes, including IT service management and customer support. This vulnerability allows an unauthorized user, under specific conditions, to execute arbitrary code within the platform. The implications of such an exploit can be dire; it may enable attackers to manipulate system functionality, access sensitive data, and disrupt essential services. The vulnerability has been addressed through security updates that ServiceNow deployed to both hosted and self-hosted customers, emphasizing the importance of immediate remediation to safeguard organizational infrastructure.

Potential impact of CVE-2026-6875

  1. Unauthorized Code Execution: The core risk associated with CVE-2026-6875 is the ability for unauthenticated users to run malicious code. This can lead to significant system compromises, allowing attackers full control over the platform, which can severely disrupt business operations.

  2. Data Breach Risk: Exploitation of this vulnerability can potentially expose sensitive organizational data. If attackers gain control over the ServiceNow platform, they can access, alter, or exfiltrate confidential information, leading to data breaches that can impact privacy and compliance.

  3. Operational Disruption: Given that ServiceNow is integral to many organizational processes, successful exploitation may result in significant operational downtime. This could hinder productivity, affect customer interactions, and lead to a loss of revenue, thereby damaging an organization's reputation and trustworthiness.

Affected Version(s)

ServiceNow AI Platform 0

ServiceNow AI Platform 0

ServiceNow AI Platform 0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached - Help Net Security

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: AI agents are still logging in as humans Most large

1 week ago

Hackers are Actively Exploiting ServiceNow Vulnerability in the Wild

A critical ServiceNow RCE vulnerability is being actively exploited to escape the script sandbox and execute code.

2 weeks ago

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Attackers exploit CVE-2026-6875 in ServiceNow AI Platform, a pre-auth sandbox escape that could compromise instances and connected proxy servers.

2 weeks ago

References

EPSS Score

24% chance of being exploited in the next 30 days.

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 💰

    Used in Ransomware

  • 🟡

    Public PoC available

  • 📈

    Vulnerability started trending

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by It Security News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Kues - Assetnote
.