Back to Home ServiceNow Customers Urged to Patch Critical AI Platform Flaw Technology

ServiceNow Customers Urged to Patch Critical AI Platform Flaw

Published on July 21, 2026 811 views

ServiceNow customers faced renewed calls on Tuesday to patch CVE-2026-6875, a critical AI Platform security flaw, after a threat intelligence company reported seeing attempts to exploit it. Defused Cyber said activity had appeared in the wild, although ServiceNow told SecurityWeek that its investigation had not linked the reported activity to instances hosted by the company.

The vulnerability carries a CVSS 4.0 score of 9.5 and can allow an unauthenticated remote user to run code in certain circumstances. ServiceNow disclosed it on July 13 after previously distributing fixes across affected product families. The company applied security updates to hosted environments and made patches available to self-hosted customers and partners.

Researchers describe CVE-2026-6875 as an escape from a restricted code-execution environment. Searchlight Cyber said it reported the issue on April 1 and warned that a successful attack could compromise a ServiceNow instance and connected proxy servers. The NIST database associates the flaw with improper control of code generation and says exploitation could severely affect data confidentiality, integrity and system availability.

Public analysis links the observed requests to a pre-authentication web endpoint and to proof-of-concept material released after the fixes became available. Defused first believed the captured payload followed a variation of the published method, but later said the sample matched the public proof of concept. No attacker identity, victim list or confirmed criminal campaign has been disclosed.

The fixed releases include Australia Patch 2, Yokohama Patch 12 Hot Fix 1b and Patch 13, Zurich Patch 7b and Patch 9, and Brazil EA and GA. Versions earlier than the relevant release remain affected. ServiceNow has encouraged both hosted and self-hosted customers to verify their patch level, while Canadian cyber authorities have also advised administrators to install the updates.

Security teams should prioritize exposed self-hosted systems, confirm the installed family release and examine application logs for unexpected traffic to the affected interface. The report of exploitation raises the urgency, but the available evidence remains limited. ServiceNow said it would continue helping customers deploy the fixes as investigators assess whether the activity reflects hostile attacks or security testing.

Sources: ServiceNow, NIST National Vulnerability Database, The Hacker News, SecurityWeek, Defused Cyber, Searchlight Cyber, Canadian Centre for Cyber Security

Comments