ServiceNow fixed a critical security hole in its AI platform that could let an outsider run malicious code without logging in. The flaw, CVE-2026-6875, has a CVSS score of 9.5 and affects ServiceNow AI platform deployments; ServiceNow says it pushed fixes to hosted instances and provided updates to self-hosted customers and partners. The company said it is not aware of active exploitation.
Why it matters: Organizations using ServiceNow's AI platform should verify the update has been applied, especially self-hosted deployments, because unauthenticated code execution can lead to full system compromise. This is the kind of flaw that should be patched quickly even without confirmed in-the-wild attacks.
Ionut Arghire
2026.07.15
100% relevant
The article establishes a distinct patch event centered on a newly disclosed critical ServiceNow AI platform vulnerability, with specific CVE details and remediation status.
← Back to all stories