dArtBook a call
all news
The Hackers News · July 21, 2026

ServiceNow AI Platform Bug Under Active Attack—Patch Now

ServiceNow AI Platform Bug Under Active Attack—Patch Now

A critical vulnerability in ServiceNow’s AI Platform is being actively exploited in the wild, according to threat intelligence firm Defused Cyber. The flaw, tracked as CVE-2026-6875 and carrying a CVSS score of 9.5, allows an unauthenticated attacker to escape the platform’s sandbox and execute arbitrary code on affected systems. Defused reported seeing real-world attacks targeting the bug shortly after its disclosure.

ServiceNow released patches throughout June covering multiple versions, including Brazil EA and GA, Australia Patch 2, Zurich Patch 7b and 9, and Yokohama Patch 12 Hot Fix 1b and Patch 13. Security firm Searchlight Cyber, which first reported the issue on April 1, 2026, warned that successful exploitation could lead to a full compromise of the ServiceNow instance and any connected proxy servers. Researcher Adam Kues noted that ServiceNow is also tightening sandbox restrictions to prevent similar code execution in the future.

According to Defused, attackers are hitting the same pre-authentication endpoint—"/assessment_thanks.do"—using HTTP POST requests. While the entry point is familiar, the sandbox-escape gadget takes a different route than previous exploits to achieve code execution. For customers running self-hosted versions of ServiceNow, applying the latest patches is strongly advised to block these ongoing attacks before systems are compromised.

Source: The Hackers News

Want a self-updating feed like this on your site?

dArt Studio installs AI for local businesses in Broward & Palm Beach County, FL. We reply within 1 business hour.