bleeping-computer · Crawled Jul 20, 2026
Critical ServiceNow code execution flaw now exploited in attacks
1 IoCs
Read original article ↗
AI Summary
Attackers are actively exploiting a critical remote code execution vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, allowing unauthenticated threat actors to escape the sandbox and execute arbitrary code. The flaw was patched on July 13, 2026, but exploitation was confirmed in the wild just days later. Despite ServiceNow not officially acknowledging active exploitation, threat intelligence firm Defused has observed attack attempts leveraging the same endpoint used in the vulnerability proof-of-concept.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | assessment_thanks[.]do | Details → |