A critical flaw in the ServiceNow AI Platform is now being exploited in real-world attacks, security researchers warn — a serious escalation given how deeply ServiceNow is embedded across large enterprises. The bug, CVE-2026-6875, allows unauthenticated attackers to break out of the platform's sandbox and run code remotely.

The vulnerability

Searchlight Cyber, which reported the flaw on April 1, describes it as letting "unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform." Because it requires no credentials, exploitation needs only network reach to a vulnerable endpoint — the most dangerous class of bug for internet-facing enterprise software.

Patched, then hunted

ServiceNow issued a fix on July 13. Days later, threat-intelligence firm Defused confirmed active exploitation first observed over the weekend of July 17-19 — and noted a telling detail: attackers reached the same vulnerable endpoint by "a different route than their published PoC," suggesting adversaries adapted the public research rather than simply replaying it. The gap between patch release and exploitation was days, not weeks.

Why the blast radius is large

ServiceNow is not a niche tool. Its platform underpins IT, HR and operations workflows at roughly 85% of the Fortune 500 and processes more than 100 billion workflows a year. A pre-authentication code-execution hole in the AI layer of software that central gives attackers a potential foothold into the connective tissue of thousands of major organizations.

What defenders should do

The immediate action is straightforward: apply ServiceNow's July 13 patch and hunt for signs of exploitation, since attackers are already probing endpoints in ways that diverge from the public proof-of-concept. The episode is also a reminder that AI features bolted onto mission-critical platforms expand the attack surface — and that the window between disclosure and exploitation keeps shrinking.